CVE-2018-7705: Securenvoy Securmail
High severity, CVSS 8.1. EPSS: 6% chance of exploitation in the next 30 days.
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mail messages to arbitrary recipients via a .. (dot dot) in the filename parameter to secupload2/upload.aspx.
Affected products
- Securenvoy Securmail: before 9.2.501 (fixed in 9.2.501)
Published 2018-03-15. Last modified 2026-06-17.