CVE-2022-42136: Path Traversal
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42136?
CVE-2022-42136 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2022-42136?
To fix CVE-2022-42136, update your MailEnable installation to a version that addresses this vulnerability.
Who is affected by CVE-2022-42136?
CVE-2022-42136 affects authenticated mail users of MailEnable versions prior to 9.0 and between 9.0 and 10.42.
What type of attack can be executed through CVE-2022-42136?
CVE-2022-42136 allows an attacker to upload unsanitized files that may lead to remote code execution.
Can CVE-2022-42136 be exploited without authentication?
No, exploitation of CVE-2022-42136 requires authenticated access to the MailEnable system.