Acmailer
by acmailer
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-20618 | Cri | 0.64 | 9.8 | 0.03 | Jan 14, 2021 | Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remote attackers to bypass authentication and to gain an administrative privilege which may result in obtaining the sensitive information on the server via… | ||
| CVE-2021-20617 | Cri | 0.64 | 9.8 | 0.08 | Jan 14, 2021 | Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative privilege which may result in obtaining the sensitive information on the server… | ||
| CVE-2026-70408 | Hig | 0.57 | 8.8 | — | Aug 19, 2026 | An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. | ||
| CVE-2026-66358 | Med | 0.40 | 6.1 | — | Aug 19, 2026 | A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. |
- risk 0.64cvss 9.8epss 0.03
Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remote attackers to bypass authentication and to gain an administrative privilege which may result in obtaining the sensitive information on the server via…
- risk 0.64cvss 9.8epss 0.08
Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative privilege which may result in obtaining the sensitive information on the server…
- risk 0.57cvss 8.8epss —
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.
- risk 0.40cvss 6.1epss —
A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.