High severity8.8NVD Advisory· Published Jan 13, 2023· Updated Jun 17, 2026
CVE-2022-42136
CVE-2022-42136
Description
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise:*:*:*+ 4 more
- cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise:*:*:*range: <8.66
- cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise_premium:*:*:*range: <8.66
- cpe:2.3:a:mailenable:mailenable:*:*:*:*:professional:*:*:*range: <8.66
- cpe:2.3:a:mailenable:mailenable:*:*:*:*:standard:*:*:*range: <8.66
- (no CPE)
Patches
Vulnerability mechanics
References
2- pastebin.com/ahLNMf5nnvdThird Party Advisory
- www.mailenable.com/kb/content/article.aspnvdVendor Advisory
News mentions
0No linked articles in our index yet.