CVE-2021-46686

CRITICAL

acmailer <4.0.3-1.1.5 - Command Injection

Title source: llm
STIX 2.1

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI ver.4.0.3 and earlier and acmailer DB ver.1.1.5 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0136
EPSS Percentile 68.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
Extra Innovation Inc./acmailer CGI ver.4.0.3 and earlier
Extra Innovation Inc./acmailer DB ver.1.1.5 and earlier
Published Feb 18, 2025
Tracked Since Feb 18, 2026