GHSA-vc6q-ccj9-9r89
CRITICALCVE-2024-27448MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the routes.js file.
- Affected
- >= 2.0.0-beta1, <= 2.1.0
- Fixed in
- not stated
- Weakness
- CWE-22
- Published
- 2024-04-05
- Source
- github