PT-2026-6819 · Amss++ · Amss++

Indoushka

·

Published

2026-02-06

·

Updated

2026-02-07

·

CVE-2020-37141

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions AMSS++ version 4.31
Description AMSS++ version 4.31 has a SQL injection issue in the mail module’s maildetail.php script. The issue is present through the id parameter. An attacker can manipulate the id parameter in the /modules/mail/main/maildetail.php script to inject malicious SQL queries, potentially allowing access or modification of database contents.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the maildetail.php script or the id parameter within that script until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-37141

Affected Products

Amss++