PT-2022-25504 · Unknown · Mail Sqr Expert System

Cyku Hong

·

Published

2022-10-31

·

Updated

2025-05-05

·

CVE-2022-40742

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mail SQR Expert system (affected versions not specified)
Description The issue allows an unauthenticated remote attacker to execute arbitrary PHP files with a .asp file extension under specific system paths. This can lead to accessing and modifying partial system information, although it does not affect service availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-40742

Affected Products

Mail Sqr Expert System