An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
https://herolab.usd.de/security-advisories/ | third party advisory |
https://herolab.usd.de/en/security-advisories/usd-2023-0015/ | third party advisory exploit |