Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46279
HistoryApr 08, 2024 - 10:52 a.m.

Remote Code Execution

2024-04-0810:52:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
maildev
remote code execution
vulnerability
input validation
email attachment
sanitization
lib/mailserver.js
routes.js

AI Score

7.7

Confidence

High

EPSS

0

Percentile

15.5%

maildev is vulnerable to Remote Code Execution. The vulnerability is due to insufficient input validation and sanitization of crafted Content-ID header for an e-mail attachment, resulting in lib/mailserver.js writing arbitrary code into the routes.js file.

AI Score

7.7

Confidence

High

EPSS

0

Percentile

15.5%