CVE-2023-40747

HIGH

A.K.I Software's PMailServer/PMailServer2 - Path Traversal

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability exists in A.K.I Software's PMailServer/PMailServer2 products' CGIs included in Internal Simple Webserver. If this vulnerability is exploited, a remote attacker may access arbitrary files outside DocumentRoot.

References (2)

Core 2
Core References
Third Party Advisory
https://jvn.jp/en/jp/JVN92720882/

Scores

CVSS v3 7.5
EPSS 0.0097
EPSS Percentile 57.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (5)
A.K.I Software/pmman.exe (Enterprise edition) 2.5.1.12158 and earlier
A.K.I Software/pmman.exe (Pro + IMAP4 edition) 2.5.1.12157 and earlier
A.K.I Software/pmman.exe (Pro edition) 2.5.1.12155 and earlier
A.K.I Software/pmman.exe (Standard + IMAP4 edition) 2.5.1.12156 and earlier
A.K.I Software/pmman.exe (Standard edition) 2.5.1.12154 and earlier
Published Mar 18, 2024
Tracked Since Feb 18, 2026