Impact
The vulnerability resides in the pmg-api package changelog retrieval endpoint. User‑supplied arguments are concatenated into an apt‑get command without proper sanitization. This allows an authenticated attacker exploiting a CSRF‑style vector to inject arbitrary parameters, potentially executing commands or accessing sensitive logs. The flaw does not provide immediate remote code execution but can lead to unauthorized information disclosure or further compromise if combined with other weaknesses.
Affected Systems
The affected product is Proxmox Mail Gateway API (pmg-api). No specific version range is listed. Any deployment of the Proxmox Mail Gateway that runs pmg‑api is potentially impacted.
Risk and Exploitability
The CVSS base score of 4.4 indicates moderate overall risk with the primary impact being exploitation of a privileged API. Because the flaw requires authentication and relies on CSRF, the effective attack surface is limited to users who have valid session cookies. EPSS is not available and the vulnerability is not in the CISA KEV list, suggesting that widespread exploitation has not yet been observed. Still, organizations should consider the risk moderate due to the potential for unauthorized information disclosure.
OpenCVE Enrichment