// For flags

CVE-2019-7213

 

Severity Score

6.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary files or could create files in new folders in arbitrary locations on the mail server. This could lead to command execution on the server for instance by putting files inside the web directories.

SmarterTools SmarterMail versión 16.x anterior a la compilación 6985, permite el salto de directorios (directory traversal). Un usuario autenticado podría suprimir archivos arbitrarios o podría crear archivos en nuevas carpetas en ubicaciones arbitrarias en el servidor de correo. Esto podría conllevar a la ejecución de comandos en el servidor, por ejemplo, al colocar archivos dentro de los directorios web.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-29 CVE Reserved
  • 2019-04-24 CVE Published
  • 2022-09-11 First Exploit
  • 2024-08-04 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Smartertools
Search vendor "Smartertools"
Smartermail
Search vendor "Smartertools" for product "Smartermail"
>= 16.0.6345 < 16.3.6985
Search vendor "Smartertools" for product "Smartermail" and version " >= 16.0.6345 < 16.3.6985"
-
Affected