Cross-site scripting in MAIL2000 - CVE-2019-15072
Published: November 20, 2019
MAIL2000
Detailed vulnerability description
The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via any parameter in the "/cgi-bin/portal" file. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
How to mitigate CVE-2019-15072
Sources
- https://gist.github.com/chtsecurity/b3396500d4686ad47fb26f64967ef24a
- https://gist.github.com/tonykuo76/5bf1ac369d953d5276afe0a2d04c2147
- https://tvn.twcert.org.tw/taiwanvn/TVN-201909002
- https://www.chtsecurity.com/download/0837ce00c27c73dd3ba3a0d4a7df3a41aaea1ac1e9831a5d61bb64ed484a3598.txt
- https://www.openfind.com.tw/taiwan/resource.html
- https://www.twcert.org.tw/en/cp-128-3086-ff35d-2.html