CVE-2020-11804
Summary
| CVE | CVE-2020-11804 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-17 17:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided directly by an authenticated user via an HTTP GET request. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SpamTitan 7.07 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory |
| SensePost | Clash of the (spam)titan | MISC | sensepost.com | Exploit, Third Party Advisory |
| Felipe Molina (felmoltor) on Twitter | MISC | twitter.com | Third Party Advisory |
| felmoltor (Felipe Molina) · GitHub | MISC | github.com | Third Party Advisory |
| SpamTitan Email Security and Anti-Spam Solution: 500 5-Star Reviews | MISC | www.spamtitan.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.