CVE-2019-12927: Mailenable

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.

Affected products

  • Mailenable Mailenable: from 6.0, before 6.90 (fixed in 6.90); from 7.0, before 7.62 (fixed in 7.62); from 8.00, before 8.64 (fixed in 8.64); from 9.0, before 9.83 (fixed in 9.83); from 10.00, before 10.24 (fixed in 10.24)

Published 2019-07-08. Last modified 2026-06-17.