CVE-2022-42136

HIGH

MailEnable < 8.66 - Authenticated Remote Code Execution via Public Folder File Upload

Title source: llm
STIX 2.1

Description

Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0087
EPSS Percentile 54.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
mailenable/mailenable < 8.66 (4 CPE variants)
Published Jan 13, 2023
Tracked Since Feb 18, 2026