PT-2023-30808 · Softnext · Softnext Mail Sqr Expert

Published

2023-12-15

·

Updated

2023-12-20

·

CVE-2023-48381

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Softnext Mail SQR Expert (affected versions not specified)
Description The issue is a Local File Inclusion (LFI) vulnerability in a special URL, allowing an unauthenticated remote attacker to execute arbitrary PHP files with .asp file extension under specific system paths. This can lead to accessing and modifying partial system information without affecting service availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-48381

Affected Products

Softnext Mail Sqr Expert