CVE-2019-12925: Mailenable
High severity, CVSS 8.1. EPSS: 1.8% chance of exploitation in the next 30 days.
MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or potentially read files in arbitrary folders accessible by the IIS user. This could lead to reading other users' credentials including those of SYSADMIN accounts, reading other users' emails, or adding emails or files to other users' accounts.
Affected products
- Mailenable Mailenable: from 6.0, before 6.90 (fixed in 6.90); from 7.0, before 7.62 (fixed in 7.62); from 8.00, before 8.64 (fixed in 8.64); from 9.0, before 9.83 (fixed in 9.83); from 10.00, before 10.24 (fixed in 10.24)
Published 2019-07-08. Last modified 2026-06-17.