SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.
View the template here CVE-2020-11546.yaml
References:
https://blog.to.com/advisory-superwebmailer-cve-2020-11546/