High severity7.5NVD Advisory· Published Dec 13, 2019· Updated Jun 17, 2026
CVE-2019-17123
CVE-2019-17123
Description
The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, the message parameter can have initial HTML comment characters.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 11+
- eGain/Web Email APIdescription
Patches
Vulnerability mechanics
References
2- medium.com/maverislabs/cve-2019-17123-cbc946c99f8nvdExploitThird Party Advisory
- www.egain.com/products/email-management-software/nvdProductVendor Advisory
News mentions
0No linked articles in our index yet.