Vulnerabilities (CVE)

Filtered by vendor Softnext Subscribe
Filtered by product Mail Sqr Expert
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-48380 1 Softnext 1 Mail Sqr Expert 2023-12-21 N/A 8.0 HIGH
Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote attacker authenticated as a localhost can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.
CVE-2023-48378 1 Softnext 1 Mail Sqr Expert 2023-12-21 N/A 7.5 HIGH
Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.