CVE-2020-11699

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
17/09/2020
Last modified:
21/07/2021

Description

An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting with this page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:titanhq:spamtitan:7.07:*:*:*:*:*:*:*