superwebmailer Vulnerabilities and Affected Products
Vulnerabilities associated with superwebmailer.
Products
Clear product- superwebmailer2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-38192MEDIUM | superwebmailer superwebmailer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords. | CVSS6.1v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-11546CRITICAL | superwebmailer superwebmailer Improper Control of Generation of Code ('Code Injection')SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection. | CVSS9.8v3.1 | EPSS32.8% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |