Cybonet - PineApp Mail Relay Unauthenticated Sql Injection
CVE-2022-22794
6.8MEDIUM
What is CVE-2022-22794?
Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 and by doing that, the attacker can run Remote Code Execution in one liner.
Affected Version(s)
Pineapp Mail Relay PineApp Latest
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dudu Moyal - Sophtix Security LTD
Gad Abuhatzeira - Sophtix Security LTD