Record summary

CVE-2020-11546 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 22, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubOfficial-BlackHat13/CVE-2020-11546Repository PoCby Official-BlackHat13Stars: 1Not analyzed2 files

3.1 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALSuperWebmailer 7.21.0.01526 - Remote Code ExecutionCVSS 9.8

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.

Remediation

Upgrade to the latest version of SuperWebmailer to mitigate this vulnerability.

WeaknessesCWE-94
AuthorsOfficial_BlackHat13
Template tagscvecve2020rcesuperwebmailervkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:superwebmailer:superwebmailer:*:*:*:*:*:*:*:*
Shodan: title:"SuperWebMailer"
Shodan: http.title:"superwebmailer"
FOFA: title="superwebmailer"
Google: intitle:"superwebmailer"

Source: ProjectDiscovery

References

2