CVE-2024-58302
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
11/12/2025
Last modified:
11/12/2025
Description
FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrary server files in email templates. Attackers can exploit the template settings by inserting file inclusion payloads to read sensitive system files like /etc/passwd during email generation.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM



