CVE-2020-25849

HIGH

Openfind MailGates and MailAudit - Authenticated OS Command Injection via CGI Parameter

Title source: llm
STIX 2.1

Description

MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4118-6292c-1.html

Scores

CVSS v3 8.8
EPSS 0.0220
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (4)
openfind/mailaudit 4.0
openfind/mailaudit 5.0
openfind/mailgates 4.0
openfind/mailgates 5.0
Published Nov 01, 2020
Tracked Since Feb 18, 2026