Easyuse · Easyuse Mailhunter Ultimate · CVE-2023-34210
**Name of the Vulnerable Software and Affected Versions**
EasyUse MailHunter Ultimate versions 2023 and earlier
**Description**
The issue allows remote authenticated users to execute arbitrary SQL commands via the `ctl00$ContentPlaceHolder1$txtCustSQL` parameter in the create customer group function. This enables attackers to manipulate the database, potentially leading to data breaches or other malicious activities.
**Recommendations**
For EasyUse MailHunter Ultimate versions 2023 and earlier, consider restricting access to the create customer group function until a patch is available. As a temporary workaround, avoid using the `ctl00$ContentPlaceHolder1$txtCustSQL` parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.