Showing 2 vulnerabilities on this page for superwebmailer

Signals CISA KEV Ransomware Nuclei
superwebmailer vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

superwebmailer superwebmailer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.

CWE-79Oct 21, 20231 related artifact
CVSS6.1v3.1EPSS1.12%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

superwebmailer superwebmailer Improper Control of Generation of Code ('Code Injection')

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

CWE-74CWE-94Jul 14, 20201 related artifact
CVSS9.8v3.1EPSS32.8%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX