MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.
Fixes

Solution

Update Patch to 5.2.8.048 version.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-09-16T23:05:21.105Z

Reserved: 2020-09-23T00:00:00

Link: CVE-2020-25849

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-01T17:15:12.200

Modified: 2024-11-21T05:18:54.073

Link: CVE-2020-25849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.