AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-12938

MEDIUM · CVSS 4.3 EPSS 1.01%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-06-24 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-12938
Severity
MEDIUM
CVSS
4.3
EPSS
1.01%
Apache Nginx

Original NVD Description

The Roundcube component of Analogic Poste.io 2.1.6 uses .htaccess to protect the logs/ folder, which is effective with the Apache HTTP Server but is ineffective with nginx. Attackers can read logs via the webmail/logs/sendmail URI.