Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 15.0.2.1
affected
Description
SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval.
Problem types
CWE-95 Improper neutralization of directives in dynamically evaluated code ('eval injection')
Product status
Any version before 15.0.2.1
References
downloads.seppmail.com/extrelnotes/150/ERN15.0.html