Medium severity6.1NVD Advisory· Published Jul 8, 2019· Updated Jun 17, 2026
CVE-2019-12927
CVE-2019-12927
Description
MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise_premium:*:*:*Range: >=6.0,<6.90
- MailEnable/MailEnable Enterprise Premiumdescription
- Range: =10.23
Patches
Vulnerability mechanics
References
2- www.mailenable.com/Premium-ReleaseNotes.txtnvdRelease NotesVendor Advisory
- www.nccgroup.trust/uk/our-research/technical-advisory-multiple-vulnerabilities-in-mailenable/nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.