.. / CVE-2020-11546

Exploit for SuperWebmailer 7.21.0.01526 - Remote Code Execution (CVE-2020-11546)

Description:

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

Nuclei Template

View the template here CVE-2020-11546.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-11546.yaml
Copy

References:

https://blog.to.com/advisory-superwebmailer-cve-2020-11546/
https://github.com/ARPSyndicate/kenzer-templates
https://github.com/Official-BlackHat13/CVE-2020-11546/
https://nvd.nist.gov/vuln/detail/CVE-2020-11546
https://github.com/HimmelAward/Goby_POC