peter bassill · operator
$ cve CVE-2020-11804 JSON

CVE-2020-11804 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided directly by an authenticated user via an HTTP GET request.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS7.11% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2020-09-17
Last modified2026-06-17

Affected (1)

VendorProduct
titanhqspamtitan

Public exploits

SourceTitleDate
exploit-dbSpamTitan 7.07 - Remote Code Execution (Authenticated)2020-09-18

References

→ the Explorer  ·  watch your stack  ·  NVD