PT-2023-30809 · Softnext · Softnext Mail Sqr Expert

CVE-2023-48382

·

Publicado

2023-12-15

·

Atualizado

2023-12-21

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Softnext Mail SQR Expert (affected versions not specified)
Description The issue is related to a Local File Inclusion (LFI) vulnerability in a mail deliver-related URL. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP files with .asp file extension under specific system paths, allowing access and modification of partial system information without affecting service availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-48382

Produtos afetados

Softnext Mail Sqr Expert