Vulnerabilities > Mailcow

DATE CVE VULNERABILITY TITLE RISK
2022-05-20 CVE-2022-31245 OS Command Injection vulnerability in Mailcow Mailcow: Dockerized
mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.
network
low complexity
mailcow CWE-78
8.8
2017-05-14 CVE-2017-8928 Cross-Site Request Forgery (CSRF) vulnerability in Mailcow Mailcow: Dockerized 0.14
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.
network
low complexity
mailcow CWE-352
8.8