CVE-2022-42136

Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
mailenablemailenable
𝑥
< 8.66
mailenablemailenable
𝑥
< 8.66
mailenablemailenable
𝑥
< 8.66
mailenablemailenable
𝑥
< 8.66
mailenablemailenable
9.0 ≤
𝑥
< 9.85
mailenablemailenable
9.0 ≤
𝑥
< 9.85
mailenablemailenable
9.0 ≤
𝑥
< 9.85
mailenablemailenable
9.0 ≤
𝑥
< 9.85
mailenablemailenable
10.00 ≤
𝑥
< 10.42
mailenablemailenable
10.00 ≤
𝑥
< 10.42
mailenablemailenable
10.00 ≤
𝑥
< 10.42
mailenablemailenable
10.00 ≤
𝑥
< 10.42
𝑥
= Vulnerable software versions