PT-2022-26018 · Unknown · Raiden Maild Mail Server

Mason Yang

·

Published

2022-11-29

·

Updated

2022-12-01

·

CVE-2022-41675

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Raiden MAILD Mail Server (affected versions not specified)
Description A remote attacker with general user privilege can inject malicious code in the form content of the Raiden MAILD Mail Server website. When other users export the form content as a CSV file, it can trigger arbitrary code execution, allowing the attacker to perform arbitrary system operations or disrupt the service on the user side.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-41675

Affected Products

Raiden Maild Mail Server