Hacker News new | ask | show | jobs
Critical (CVSS 10) tagged CVE-2025-52691 affecting SmarterMail software (github.com)
1 points by runtimepanic 164 days ago
1 comments

SmarterMail Build 9406 and earlier is vulnerable to arbitrary file upload. An unauthenticated attacker can upload arbitrary files to any location on the mail server, potentially enabling remote code execution.