CVE-2020-14932: Squirrelmail

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.php.

Affected products

Published 2020-06-20. Last modified 2026-06-17.