CVE-2018-18703: Phptpoint Mailing Server Using File Handling
High severity, CVSS 7.5. EPSS: 4.1% chance of exploitation in the next 30 days.
PhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different sections that allow an attacker to read sensitive files on the system via directory traversal, bypassing the login page, as demonstrated by the Mailserver_filesystem/home.php coninb, consent, contrsh, condrft, or conspam parameter.
Affected products
- Phptpoint Mailing Server Using File Handling: version 1.0 only
Published 2018-10-29. Last modified 2026-06-17.