PT-2025-20165 · Yaysmtp · Yaysmtp

Chuongvn

·

Published

2025-05-07

·

Updated

2025-05-07

·

CVE-2025-47587

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions YaySMTP versions n/a through 2.6.4
Description The issue is related to an Improper Neutralization of Special Elements used in an SQL Command, also known as SQL Injection. This allows for Blind SQL Injection, which can be exploited.
Recommendations For YaySMTP versions n/a through 2.6.4, update to a version later than 2.6.4 to resolve the issue. At the moment, there is no information about additional mitigation measures for this specific vulnerability.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-47587

Affected Products

Yaysmtp