S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-7219 Scanner

CVE-2019-7219 scanner - Cross-Site Scripting (XSS) vulnerability in Zarafa Webapp

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-7219
6.1
CVSS

Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Zarafa Webapp is a discontinued product that was used as a groupware solution for email, calendar and contact management. This product was widely utilized by businesses and organizations as a centralized platform for communication and collaboration. Zarafa Webapp provided a user-friendly interface and was compatible with various operating systems including Windows, Linux, and MacOS.

CVE-2019-7219 was a vulnerability detected in Zarafa Webapp 2.0.1.47791 and earlier versions. This vulnerability allowed unauthenticated reflected cross-site scripting (XSS) attacks. This means a hacker could exploit this vulnerability to inject malicious code into a victim's web browser and steal sensitive information, such as login credentials and financial data, or perform actions on behalf of the victim without their consent.

When exploited, the CVE-2019-7219 vulnerability posed a severe threat to the security of businesses and organizations who used Zarafa Webapp. Any user, including employees, contractors, and clients, could be targeted by a hacker and their information could be compromised. Moreover, the reputation of the organization could also be at risk since customers' information could be stolen, resulting in potential legal and financial consequences.

Finally, by utilizing the pro features of the s4e.io platform, businesses and organizations can easily and quickly learn about vulnerabilities in their digital assets. With features such as automated vulnerability scanning and personalized security reports, users of this platform are equipped with the necessary tools to strengthen their digital security posture and protect against malicious attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended to take the following precautions:

  • Ensure that all Zarafa Webapp software is updated to the latest version that includes the CVE-2019-7219 patch.
  • Educate employees on how to spot and avoid phishing emails and malicious links.
  • Implement a network security solution that includes anti-malware features and attack detection and prevention tools.
  • Conduct regular vulnerability assessments and penetration testing to identify any other vulnerabilities and address them promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-7219 scanner - Cross-Site Scripting (XSS) vulnerability in Zarafa Webapp | S4E