MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-18482 | MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token. |
Fixes
Solution
Update Patch to 5.2.8.048 version.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4118-6292c-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T23:05:21.105Z
Reserved: 2020-09-23T00:00:00
Link: CVE-2020-25849
No data.
Status : Modified
Published: 2020-11-01T17:15:12.200
Modified: 2024-11-21T05:18:54.073
Link: CVE-2020-25849
No data.
OpenCVE Enrichment
No data.
EUVD