CVE-2021-20617
Acmailer and Acmailer DB Survey Function Vulnerability
Record summary
CVE-2021-20617 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative privilege which may result in obtaining the sensitive information on the server via unspecified vectors.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 5, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
acmailer and acmailer DBBrowse Seeds Co.,Ltd. / acmailer and acmailer DB | CVE List | acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier | affected |
acmailerBrowse acmailer / acmailer | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALAcmailer - Improper Access Control to OS Command InjectionCVSS 9.8
Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative privilege which may result in obtaining the sensitive information on the server via unspecified vectors.
Impact
Attackers can execute arbitrary OS commands or escalate privileges, potentially leading to full system compromise and sensitive data exposure.
Remediation
Update to the latest version of acmailer and acmailer DB to address the issue.
Source: ProjectDiscovery