PT-2020-3997 · Acymailing · Acymailing

Published

2020-03-24

·

Updated

2023-02-03

·

CVE-2020-10934

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: AcyMailing versions prior to 6.9.2
Description: The issue is related to the lack of restrictions on file uploads in the AcyMailing mail manager. This can be exploited by a remote attacker to execute arbitrary code. The problem arises from the mishandling of file uploads by administrators.
Recommendations: For versions prior to 6.9.2, update to version 6.9.2 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities for administrators until the update is applied.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2020-04391
CVE-2020-10934

Affected Products

Acymailing