LiveActive security incident?Get immediate response
CVE Record

CVE-2017-9519: atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.

atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Older atmail versions before 7.8.0.2 had a CSRF flaw that could let an attacker cause a user account to be created. That matters because unauthorized accounts can become a foothold for further access. The provided sources do not include a CVSS score, exploit details, or evidence of active exploitation.

Executive priority

Handle as a moderate remediation item. Unauthorized account creation can create business risk, but the provided evidence lacks severity scoring and active exploitation. Prioritize faster if atmail is externally reachable or used for sensitive mail operations.

Technical view

CVE-2017-9519 is described as CSRF in atmail before 7.8.0.2, allowing user account creation. The public bundle does not provide endpoint details, CWE mapping, CPEs, CVSS metrics, or privilege assumptions. KEV is false, and the supplied sources do not substantiate active exploitation.

Likely exposure

Exposure is likely limited to organizations running atmail versions earlier than 7.8.0.2. Risk depends on whether account-management functionality is reachable and whether privileged users operate the application in browser sessions. The supplied sources do not define affected editions or deployment conditions.

Exploitation context

The sources only state CSRF leading to account creation. They do not provide exploit status, prerequisites, proof-of-concept details, or evidence of in-the-wild attacks. Treat active exploitation as unconfirmed based on the provided bundle.

Researcher notes

The public record is sparse. Key missing details include affected CPEs, CVSS, endpoint scope, authentication assumptions, and whether account creation requires an administrator session. Avoid claims beyond atmail before 7.8.0.2 and the stated CSRF impact.

Mitigation direction

  • Upgrade atmail to version 7.8.0.2 or later where applicable.
  • Review the atmail vendor advisory for environment-specific upgrade guidance.
  • Restrict access to administrative account-management functions where feasible.
  • Review existing user accounts for unauthorized or unexpected additions.
  • Ensure operational monitoring covers account creation events.

Validation and detection

  • Inventory atmail deployments and record exact versions.
  • Confirm no production instance is older than 7.8.0.2.
  • Review account creation logs around suspicious administrative sessions.
  • Check for unexpected users, aliases, or newly provisioned mailboxes.
  • Verify vendor-recommended CSRF protections are present after upgrade.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-9519 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.