Home
MEDIUM: 6.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:LDefault status
unknown
12.1.17 (custom)
affected
Description
SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
12.1.17 (custom)
References
code-white.com/public-vulnerability-list/