Vulnerabilities > Smartertools > High

DATE CVE VULNERABILITY TITLE RISK
2022-03-14 CVE-2022-24387 Unrestricted Upload of File with Dangerous Type vulnerability in Smartertools Smartertrack
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g.
network
low complexity
smartertools CWE-434
7.2
2021-08-17 CVE-2020-29548 Command Injection vulnerability in Smartertools Smartermail
An issue was discovered in SmarterTools SmarterMail through 100.0.7537.
network
high complexity
smartertools CWE-77
8.1
2019-04-24 CVE-2019-7212 Use of Hard-coded Credentials vulnerability in Smartertools Smartermail
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys.
network
low complexity
smartertools CWE-798
8.2