9.8
CVE-2022-40741
- EPSS 2.15%
- Veröffentlicht 31.10.2022 07:15:10
- Zuletzt bearbeitet 21.11.2024 07:21:57
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system command and disrupt service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Softnext ≫ Mail Sqr Expert Version2dut.190301
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.15% | 0.837 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| twcert@cert.org.tw | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.