CVE-2025-52691
Unknown
Unknown - Not Provided
Arbitrary File Upload in Mail Server Enables Remote Code Execution
Publication date: 2025-12-29
Last updated on: 2025-12-29
Assigner: CSA
Description
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| smartertools | smartermail | 9413 |
| smartertools | smartermail | 9406 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |