Impact
A classic SQL injection flaw exists in MailData Email Archiving System version 4.2 and earlier, allowing attackers to insert malicious SQL commands through untrusted input fields. This vulnerability can lead to unauthorized access to, tampering with, or deletion of stored email data.
Affected Systems
MailData Email Archiving System 4.2 and all earlier releases are vulnerable. Systems that have not been upgraded to a post‑4.2 version remain at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity level. The EPSS score of less than 1% indicates that exploitation is currently unlikely and no public exploits have been documented. The vulnerability is not listed in CISA’s KEV catalog. Since no official fix is publicly documented, mitigation should rely on input sanitization and limiting database privileges. The likely attack vector is a web interface that accepts user‑supplied data for email archival queries; this inference comes from the nature of SQL injection and is not explicitly confirmed in the description.
OpenCVE Enrichment