The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities.
Conclusion & alert: CVE-2019-15072 is rated Moderate Risk (48.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.65%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-15 | 0.77% | 0.65% | -0.12% |
| 2 | 2025-03-30 | 0.54% | 0.77% | +0.23% |
| 3 | 2025-03-29 | — | 0.54% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| URL | Tags |
|---|---|
| https://gist.github.com/chtsecurity/b3396500d4686ad47fb26f64967ef24a | Third Party Advisory |
| https://gist.github.com/tonykuo76/5bf1ac369d953d5276afe0a2d04c2147 | Third Party Advisory |
| https://tvn.twcert.org.tw/taiwanvn/TVN-201909002 | Third Party Advisory |
| https://www.chtsecurity.com/download/0837ce00c27c73dd3ba3a0d4a7df3a41aaea1ac1e9831a5d61bb64ed484a3598.txt | Third Party Advisory |
| https://www.openfind.com.tw/taiwan/resource.html | Product Vendor Advisory |
| https://www.twcert.org.tw/en/cp-128-3086-ff35d-2.html | Third Party Advisory |