go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

SOFTNEXT TECHNOLOGIES CORP. Mail SQR Expert - Command Injection

TVN ID TVN-202210008
CVE ID CVE-2022-40741
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products SOFTNEXT TECHNOLOGIES CORP. Mail SQR Expert version 2dut.190301
Description Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system command and disrupt service.
Solution Update Mail SQR Expert version to 2dut.220701 (The version except FreeBSD 9.x device)
Credit Cyku Hong (DEVCORE)
Public Date 2022-10-26
Top