LiveActive security incident?Get immediate response
CVE archive

July 2019

Browse CVE records published in July 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1520 matching CVEs · Page 19 of 31.

Unknown · CVSS Not scored

CVE-2019-13057: An issue was discovered in the server in OpenLDAP before 2.4.48.

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

Published Jul 26, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-13024: Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to ex...

Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).

Published Jul 1, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12970: XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2.

XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element.

Published Jul 1, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12926: MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas.

MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it was possible to perform a number of actions, when logged in as a user, that that user should not have had permission to perform. It was also possible to gain access to areas within the application for which the accounts used were supposed to have insufficient access.

Published Jul 8, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12923: In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanis...

In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker.

Published Jul 8, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12925: MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authe...

MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or potentially read files in arbitrary folders accessible by the IIS user. This could lead to reading other users' credentials including those of SYSADMIN accounts, reading other users' emails, or adding emails or files to other users' accounts.

Published Jul 8, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12924: MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that coul...

MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML processor to read any file on the host system. Because all credentials were stored in a cleartext file, it was possible to steal all users' credentials (including the highest privileged users).

Published Jul 8, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12821: A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner, while adding a de...

A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner, while adding a device to the account using a QR-code. The QR-code follows an easily predictable pattern that depends only on the specific device ID of the robot vacuum cleaner. By generating a QR-code containing information about the device ID, it is possible to connect an arbitrary device and gain full access to it. The device ID has an initial "JSW" substring followed by a six digit number that depends on the specific device.

Published Jul 19, 2019 · Updated Aug 4, 2024

High · CVSS 8.8

CVE-2019-12803: Hunesion i-oneNet unrestricted file upload vulnerability

In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell to perform remote code exection such as running a system command.

Published Jul 10, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12773: An issue was discovered in Verint Impact 360 15.1.

An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to embed arbitrary content inside of an iFrame. Attackers may use this in conjunction with social engineering to embed malicious scripts or phishing pages on a site where this product is installed, given the attacker can convince a victim to visit a crafted link.

Published Jul 14, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12820: A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner.

A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner. Actions performed on the app such as changing a password, and personal information it communicates with the server, use unencrypted HTTP. As an example, while logging in through the app to a Jisiwei account, the login request is being sent in cleartext. The vulnerability exists in both the Android and iOS version of the app. An attacker could exploit this by using an MiTM attack on the local network to obtain someone's login credentials, which gives them full access to the robot vacuum cleaner.

Published Jul 19, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12782: An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2)...

An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards of another user in the application by spoofing GUIDs in pinboard update requests, effectively deleting them.

Published Jul 9, 2019 · Updated Aug 4, 2024