S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-11546 Scanner

CVE-2020-11546 scanner - Remote Code Execution (RCE) vulnerability in SuperWebMailer

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-11546
9.8
CVSS

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

SuperWebMailer is a popular email marketing software that allows businesses and individuals to send bulk emails to subscribers. This tool is often used for promotional activities, announcements, and newsletters. It offers a range of features, including customizable templates, mailing lists, and tracking capabilities. The software boasts ease of use, convenience, and affordability, making it a popular choice for many marketers.

However, there is an inherent risk associated with the use of SuperWebMailer. The CVE-2020-11546 vulnerability detected in the system’s mailingupgrade.php can allow an unauthenticated remote attacker to execute arbitrary PHP code via Code Injection. This means that an attacker can inject malicious code into the software, causing damage to the organization's data, systems, and web servers.

When exploited, this vulnerability can lead to severe consequences, such as data breaches, theft of sensitive information, and even complete system compromise. Attackers can use the vulnerability to gain unauthorized access to the email system, inject malware, or carry out phishing campaigns. The impact of such attacks can be catastrophic for businesses, leading to reputational damage, financial losses, and legal liabilities.

As a final point, it is worth noting that with the pro features of the S4E platform, businesses and individuals can easily and quickly learn about vulnerabilities in their digital assets. The platform offers comprehensive security testing, risk assessment, and reporting capabilities to help organizations identify and mitigate potential vulnerabilities. By using tools like this, businesses and individuals can protect their assets from cyber threats and maintain their credibility over the long term.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against the CVE-2020-11546 vulnerability, including:

  • Update the SuperWebMailer software to the latest version that includes security patches.
  • Implement a web application firewall (WAF) to detect and block attacks against the software.
  • Enable strong authentication mechanisms, such as two-factor authentication, to prevent unauthorized access to the system.
  • Regularly perform security audits and vulnerability assessments to identify and fix any security weaknesses in the software.
  • Train employees on the importance of good cyber hygiene, such as avoiding clicking on suspicious links or opening attachments from unknown sources.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-11546 scanner - Remote Code Execution (RCE) vulnerability in SuperWebMailer S4E