GHSA-wc7f-vvj8-28m9High
SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection...
🔗 CVE IDs covered (1)
📋 Description
SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressions and potentially achieve remote code execution depending on the enabled template plugins.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-44129
- https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#security
- https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128
- https://github.com/advisories/GHSA-wc7f-vvj8-28m9