AcyMailing Vulnerabilities and Affected Products
Vulnerabilities associated with acymailing.
Products
Clear product- Newsletter Plugin for Joomla in the Enterprise version2 vulnerabilities
- acymailing1 vulnerability
- Newsletter Plugin for Joomla1 vulnerability
- Newsletter via SMTP, Sendinblue, Sendgrid, Mailgun - AcyMailing SMTP Newsletter1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-7384HIGH | AcyMailing <= 9.7.2 - Authenticated (Subscriber+) Arbitrary File Upload via acym_extractArchive FunctionThe AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the acym_extractArchive function in all versions up to, and including, 9.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CWE-434Aug 22, 2024 | CVSS7.5v3.1 | EPSS0.958% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |