Security Advisory

CVE-2023-6381

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-12-13 10:46:12
Last updated 2024-08-02 08:28:21
Assigner INCIBE
State PUBLISHED

Description

Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11.20.0.2204. An attacker could exploit this vulnerability by sending a malicious configuration file (file with SMB extension) to a user via a link or email attachment and persuade the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to crash the application when attempting to load the malicious file.