CVE-2019-17123 Information

Description

The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled as demonstrated by fromName header injection with a 0a or 0d character. (Also the message parameter can have initial HTML comment characters.)

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Reference

http://www.egain.com/products/email-management-software/ https://medium.com/maverislabs/cve-2019-17123-cbc946c99f8

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

7.5

Share on: