Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial system information but does not affect service availability.
History

Mon, 05 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2022-10-31T06:40:42.545Z

Updated: 2025-05-05T15:30:22.520Z

Reserved: 2022-09-15T00:00:00.000Z

Link: CVE-2022-40742

cve-icon Vulnrichment

Updated: 2024-08-03T12:28:41.529Z

cve-icon NVD

Status : Modified

Published: 2022-10-31T07:15:10.783

Modified: 2025-05-05T16:15:20.293

Link: CVE-2022-40742

cve-icon Redhat

No data.