CyberICT

CVE-2025-52691

SmarterTools · Published December 29, 2025

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

Affected Products

  • Smartermail < 100.0.9413

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H