Security Advisory

CVE-2019-1010246

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-07-18 18:04:34
Last updated 2024-08-05 03:07:18
Assigner dwf
State PUBLISHED

Description

MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password information disclosure. The impact is: MySQL database content disclosure (e.g. username, password). The component is: The API call in the function allowAction() in NewslettersController.php. The attack vector is: HTTP Get request. The fixed version is: c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9.