漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
mailcow: dockerized vulnerable to SSTI in Quota and Quarantine Notification Template
漏洞信息
mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 2025-07 in the notification template system used by mailcow for sending quota and quarantine alerts. The template rendering engine allows template expressions that may be abused to execute code in certain contexts. The issue requires admin-level access to mailcow UI to configure templates, which are automatically rendered during normal system operation. Version 2025-07 contains a patch for the issue.
漏洞信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
漏洞
CWE-1336
漏洞
mailcow: dockerized 安全漏洞
漏洞信息
mailcow: dockerized是mailcow开源的一个docker化的mailcow应用软件。 mailcow: dockerized 2025-07之前版本存在安全漏洞,该漏洞源于通知模板系统存在服务器端模板注入,可能导致代码执行。
漏洞信息
N/A
漏洞
N/A