CVE-2020-11804
HIGHTitanhq Spamtitan - Code Injection
Title source: ruleDescription
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided directly by an authenticated user via an HTTP GET request.
Exploits (1)
exploitdb
WORKING POC
by Felipe Molina · pythonwebappsmultiple
https://www.exploit-db.com/exploits/48817
References (5)
Scores
CVSS v3
8.8
EPSS
0.0755
EPSS Percentile
91.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
titanhq/spamtitan
7.07
Published
Sep 17, 2020
Tracked Since
Feb 18, 2026