CVE-2022-41871: Command Injection
Published Apr 28, 2025
·Updated
SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.
Affected Software
2 affected components
SEPPmail SEPPmail<12.1.17
SEPPmail SEPPmail<=12.1.17
Event History
Apr 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-41871?
CVE-2022-41871 is considered a critical vulnerability due to the ability to execute arbitrary code as the root user.
2
How do I fix CVE-2022-41871?
To mitigate CVE-2022-41871, upgrade SEPPmail to version 12.1.17 or later.
3
What type of attack is associated with CVE-2022-41871?
CVE-2022-41871 is associated with command injection attacks that allow authenticated users to run arbitrary commands.
4
Who is affected by CVE-2022-41871?
Any organization using SEPPmail versions up to 12.1.17 is vulnerable to CVE-2022-41871.
5
Is authentication required to exploit CVE-2022-41871?
Yes, an attacker must be an authenticated user to exploit CVE-2022-41871.