Vulnerability CVE-2023-6381


Published: 2023-12-13   Modified: 2023-12-14

Description:
Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11.20.0.2204. An attacker could exploit this vulnerability by sending a malicious configuration file (file with SMB extension) to a user via a link or email attachment and persuade the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to crash the application when attempting to load the malicious file.

Type:

CWE-20

(Improper Input Validation)

 References:
https://www.incibe.es/en/incibe-cert/notices/aviso/improper-input-validation-newsletter-software-supermailer

Copyright 2026, cxsecurity.com

 

Back to Top