logo

Mailcow Mail Server Flaws Expose Servers to Remote Code Execution

ID: b5494d61-4fe2-5d48-b7fe-5a8fe5d7b6c0

STIX ID: report--b5494d61-4fe2-5d48-b7fe-5a8fe5d7b6c0

Feed Name: The Hacker News

Threat Score
55/100

Date Published: 2024-06-19

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Two moderate-severity vulnerabilities (CVE-2024-30270 and CVE-2024-31204) were disclosed in Mailcow prior to version 2024-04; a path traversal/command-execution issue and a stored XSS in exception handling can be combined to allow an attacker to hijack admin sessions and execute commands if an admin views a malicious email.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.