S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 18, 2025

CVE-2021-20617 Scanner

CVE-2021-20617 Scanner - OS Command Injection vulnerability in Acmailer

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-20617
9.8
CVSS

Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative privilege which may result in obtaining the sensitive information on the server via unspecified vectors.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
acmailer and acmailer DBby Seeds Co.,Ltd.
acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier
Updated Aug 21, 2026View on NVD →
Detail

Acmailer is an email marketing software used by businesses and organizations for managing email lists and sending newsletters. It enables users to create, send, and track email marketing campaigns, making it a versatile tool for digital marketing efforts. This platform is utilized by companies of varying sizes to enhance customer engagement and communication. Acmailer is often set up on servers to automate the distribution of mass emails while offering analytical insights into campaign performance. The software serves marketers and businesses seeking to optimize their email outreach in a streamlined manner. It provides tools to segment target audiences and schedule email deliveries for optimal impact.

The OS Command Injection vulnerability in Acmailer allows remote attackers to execute arbitrary operating system commands. This vulnerability stems from improper access controls in certain API endpoints. Exploitability is high as attackers can issue commands with elevated privileges, posing significant risks. Vulnerable systems may inadvertently expose sensitive information or undergo unauthorized modifications. Attackers exploiting this flaw could gain complete control over the affected server. The vulnerability is notable for its broad impact across various configurations of the Acmailer platform.

Technical details reveal that the vulnerability is present in the handling of certain HTTP POST requests. The "init_ctl.cgi" endpoint is specifically flagged as exploitable, where injected commands are embedded within user-supplied input fields. Due to insufficient validation, malicious commands bypass authentication checks, leading to the execution at the server level. This method of exploitation leverages the lack of parameter sanitization. The effectiveness of the attack is enhanced when leveraged in combination with other network tools. Discovering this endpoint and crafting a suitable payload can provide attackers with administrative privileges.

Exploiting this vulnerability can have dire consequences, including unauthorized access to sensitive data and server compromise. Once exploited, attackers may install backdoors or exfiltrate confidential information. The ensuing control could facilitate other types of cyber-attacks, such as data corruption or service disruption. The integrity of the server and its hosted applications can be significantly undermined. This vulnerability, if left unpatched, poses a critical threat requiring immediate attention. Organizations could also face reputational damage should customer data be exposed.

REFERENCES

Solution Advice
  • Update to the latest version of Acmailer and Acmailer DB to address the issue.
  • Implement input validation to sanitize user inputs.
  • Restrict access to critical scripts via robust authentication mechanisms.
  • Apply least privilege principle to limit execution environments.
  • Regularly audit and monitor logs for unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.