GHSA-wc7f-vvj8-28m9High

SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection...

Published
May 8, 2026
Last Modified
May 18, 2026

🔗 CVE IDs covered (1)

📋 Description

SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressions and potentially achieve remote code execution depending on the enabled template plugins.

🔗 References (4)