CVE-2020-11803

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
17/09/2020
Last modified:
21/07/2021

Description

An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the user-provided input is passed directly to the php eval() function. The user has to be authenticated on the web platform before interacting with the page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:titanhq:spamtitan:7.07:*:*:*:*:*:*:*