Vulnerabilities > Squirrelmail > Squirrelmail > 1.4.22

DATE CVE VULNERABILITY TITLE RISK
2017-04-20 CVE-2017-7692 Improper Input Validation vulnerability in Squirrelmail 1.4.22
SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mishandled in a popen call.
network
low complexity
squirrelmail CWE-20
8.8