High
CVSS 7.5
Overview
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the "To:" field.
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows re...
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the "To:" field.
This vulnerability is rated 🟠 HIGH.
Recommended actions: