VulnerabilityModified
CVE-2022-40742
Mail SQR Expert system has a Local File Inclusion vulnerability.
MEDIUM 6.5EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial system information but does not affect service availability.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- softnext/mail sqr expert
- Source
- twcert@cert.org.tw
References
- https://www.twcert.org.tw/tw/cp-132-6644-d7aac-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-6644-d7aac-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.