CVE-2022-40741

CRITICAL

Mail SQR Expert - Unauthenticated OS Command Injection

Title source: llm
STIX 2.1

Description

Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system command and disrupt service.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0108
EPSS Percentile 60.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
softnext/mail_sqr_expert 2dut.190301
Published Oct 31, 2022
Tracked Since Feb 18, 2026