CVE-2013-4478: Supmua Sup

Medium severity, CVSS 6.8. EPSS: 2.1% chance of exploitation in the next 30 days.

Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.

Affected products

  • Supmua Sup: up to and including 0.13.2; version 0.13.0 only; version 0.13.1 only; version 0.14.0 only; version 0.14.1 only

Published 2013-12-07. Last modified 2026-06-16.