ZeroHour

CVE-2020-11546

PoC
CVSS 3.1
9.8 critical
EPSS
33%p98
Published
()
Modified
Description

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

Vendors
superwebmailer
Products
superwebmailer
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.