Remote Code Execution Vulnerability in SuperWebMailer 7.21.0.01526 via Language Parameter in mailingupgrade.php

Remote Code Execution Vulnerability in SuperWebMailer 7.21.0.01526 via Language Parameter in mailingupgrade.php

CVE-2020-11546 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

Learn more about our Web App Pen Testing.