CVE-2023-39933: A.k.i Software Pmc.exe
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Insufficient verification vulnerability exists in Broadcast Mail CGI (pmc.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a user who can upload files through the product may execute an arbitrary executable file with the web server's execution privilege.
Affected products
- A.k.i Software Pmc.exe: up to and including 2.5.1.720
Published 2024-03-18. Last modified 2026-06-17.