First published: Wed May 07 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows Blind SQL Injection. This issue affects YaySMTP: from n/a through 2.6.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
YayCommerce YaySMTP | <=2.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-47587 is classified as high due to the potential for Blind SQL Injection.
To mitigate CVE-2025-47587, update YaySMTP to version 2.6.5 or later.
YaySMTP versions from n/a up to and including 2.6.4 are affected by CVE-2025-47587.
CVE-2025-47587 is an SQL Injection vulnerability allowing for Blind SQL Injection attacks.
The vendor for the affected software in CVE-2025-47587 is YayCommerce.