Socomec MOD3GP-SY-120K Code Injection
CVE-2023-40221
8.8HIGH
What is CVE-2023-40221?
A critical vulnerability exists in the web application of the Mail Server Application due to insufficient filtering during request processing. This weakness allows attackers to inject malicious code through the MAIL_RCV parameter. When a legitimate user accesses the NOTIFICATION section of the web application, the injected code can be executed, potentially compromising the user's session and data integrity.
Affected Version(s)
MODULYS GP (MOD3GP-SY-120K) v01.12.10
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Aarón Flecha Menéndez reported these vulnerabilities to CISA.