CVE-2020-11546
superwebmailer superwebmailer Improper Control of Generation of Code ('Code Injection')
Record summary
CVE-2020-11546 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
superwebmailerBrowse superwebmailer / superwebmailer | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubOfficial-BlackHat13/CVE-2020-11546Repository PoCby Official-BlackHat13Stars: 1Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALSuperWebmailer 7.21.0.01526 - Remote Code ExecutionCVSS 9.8
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
Remediation
Upgrade to the latest version of SuperWebmailer to mitigate this vulnerability.
Source: ProjectDiscovery