Vulnerabilities > Mailcleaner
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-07-18 | CVE-2019-1010246 | Missing Authorization vulnerability in Mailcleaner MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password information disclosure. | 7.5 |
2019-03-21 | CVE-2018-20323 | OS Command Injection vulnerability in Mailcleaner 2018.08 www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands. | 8.8 |
2018-10-24 | CVE-2018-18635 | Cross-site Scripting vulnerability in Mailcleaner 2018.08/2018.09 www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.08 and 2018.09 allows XSS via the admin/login/user/message/ PATH_INFO. | 6.1 |