Security Advisory
CVE-2020-37141
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
AMSS++ version 4.31 contains a SQL injection vulnerability in the mail modules maildetail.php script through the id parameter. Attackers can manipulate the id parameter in /modules/mail/main/maildetail.php to inject malicious SQL queries and potentially access or modify database contents.