VulnerabilityModified
CVE-2018-0685
SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail search.
HIGH 8.8EPSS 1.24%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail search.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.24% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- neo/debun pop
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN00344155/index.htmlThird Party Advisory
- https://www.denbun.com/en/imap/support/security/181003.htmlVendor Advisory
- https://www.denbun.com/en/pop/support/security/181003.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN00344155/index.htmlThird Party Advisory
- https://www.denbun.com/en/imap/support/security/181003.htmlVendor Advisory
- https://www.denbun.com/en/pop/support/security/181003.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.