PT-2020-12856 · Titanhq · Spamtitan

Published

2020-09-17

·

Updated

2021-07-21

·

CVE-2020-11803

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SpamTitan version 7.07
Description An issue was discovered where improper sanitization of the jaction parameter when interacting with the "mailqueue.php" page could lead to server-side PHP code evaluation. This occurs because user-provided input is passed directly to the php eval() function, but the user must be authenticated on the web platform before interacting with the page.
Recommendations For SpamTitan version 7.07, consider restricting access to the "mailqueue.php" page until a fix is available, and avoid using the jaction parameter in this context to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11803

Affected Products

Spamtitan