Socomec MOD3GP-SY-120K Code Injection
CVE-2023-40221

8.8HIGH

Key Information:

Vendor

Socomec

Vendor
CVE Published:
18 September 2023

What is CVE-2023-40221?

A critical vulnerability exists in the web application of the Mail Server Application due to insufficient filtering during request processing. This weakness allows attackers to inject malicious code through the MAIL_RCV parameter. When a legitimate user accesses the NOTIFICATION section of the web application, the injected code can be executed, potentially compromising the user's session and data integrity.

Affected Version(s)

MODULYS GP (MOD3GP-SY-120K) v01.12.10

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aarón Flecha Menéndez reported these vulnerabilities to CISA.
.