VYPR

AMSS++

by AMSS++

CVEs (2)

  • CVE-2020-37141HigFeb 7, 2026
    risk 0.53cvss 8.2epss 0.00

    AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' parameter. Attackers can manipulate the 'id' parameter in /modules/mail/main/maildetail.php to inject malicious SQL queries and potentially access or modify database contents.

  • CVE-2020-37135HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.