ZeroHour

CVE-2021-31988

CVSS 3.1
8.8 high
EPSS
<1%p59
Published
()
Modified
Description

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

Vendors
axis
Products
axis os, axis os 2016, axis os 2018, axis os 2020
Weakness
CWE-1286, CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.