Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade postfixadmin | Jul 30, 2024 | Oct 1, 2014 |
| Freebsd | — | Upgrade postfixadmin | Dec 10, 2025 | Jan 27, 2012 |
| Gentoo Linux | — | Upgrade www-apps/postfixadmin. | Oct 30, 2017 | Oct 1, 2014 |
| Postfix | — | Upgrade to the latest version of Postfix | Oct 9, 2014 | Oct 1, 2014 |
| Suse | — | Upgrade postfixadmin | Dec 12, 2013 | Dec 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub