ly1g3/Mailcow-CVE-2022-31245

ly1g3/Mailcow-CVE-2022-31245

Releases0
Stars12
CVE-2022-31245: RCE and domain admin privilege escalation for Mailcow

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH9 HIGH

mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.