CVE-2019-1010246 describes an unauthenticated information disclosure vulnerability in MailCleaner versions prior to c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9. An attacker can exploit an API call in the NewslettersController.php via an HTTP GET request to disclose MySQL database content, including usernames and passwords. This vulnerability has a CVSSv3 score of 7.5 (HIGH), indicating a severe impact on confidentiality with no authentication or user interaction required. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2019-01-21CPE matchmatch criteria | cpe:2.3:a:mailcleaner:mailcleaner:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.