zhonghaozhao/winmail

zhonghaozhao/winmail

Releases0

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
<= 5.1, <= 7.18.8 HIGH

An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.

= 6.56.1 MEDIUM4.3 MEDIUM

A reflected XSS vulnerability exists in tohtml/convert.php of Winmail 6.5, which can cause JavaScript code to be executed.

= 6.57.5 HIGH5 MEDIUM

A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the server to send a request to a specific URL. An attacker can modify the request header 'HOST' value to cause the server to send the request.

8.8 HIGH6.5 MEDIUM

Winmail Server 6.1 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php move_folder_file call to move a .php file from the FTP folder into a web folder.