← back
CVE-2023-24835

Softnext SPAM SQR - Code Injection

CVSS 7.2 HIGHEPSS 0.9%CWE-94
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
27 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with administrator privilege can exploit this vulnerability to execute arbitrary system command to perform arbitrary system operation or disrupt service.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Softnext · SPAM SQR

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →