PT-2025-29764 · Yaycommerce · Yaycommerce Smtp For Amazon Ses

Lê Quốc Bảo

·

Published

2025-07-16

·

Updated

2025-07-21

·

CVE-2025-54043

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions YayCommerce SMTP for Amazon SES versions n/a through 1.9
Description A SQL Injection issue exists in YayCommerce SMTP for Amazon SES. The vulnerability is due to improper neutralization of special elements used in an SQL command.
Recommendations Update YayCommerce SMTP for Amazon SES to a version later than 1.9.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-54043

Affected Products

Yaycommerce Smtp For Amazon Ses