CVE-2018-0685

HIGH

Denbun POP < 3.3p_r4.0 - Authenticated SQL Injection via Mail Search HTTP Request

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail search.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN00344155/index.html

Scores

CVSS v3 8.8
EPSS 0.0124
EPSS Percentile 66.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
neo/debun_pop < 3.3p_r4.0
Published Nov 15, 2018
Tracked Since Feb 18, 2026