CVE-2023-40747: A.k.i Software Pmman.exe Enterprise Edition
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
Directory traversal vulnerability exists in A.K.I Software's PMailServer/PMailServer2 products' CGIs included in Internal Simple Webserver. If this vulnerability is exploited, a remote attacker may access arbitrary files outside DocumentRoot.
Affected products
- A.k.i Software Pmman.exe Enterprise Edition: up to and including 2.5.1.12158
- A.k.i Software Pmman.exe Pro + IMAP4 Edition: up to and including 2.5.1.12157
- A.k.i Software Pmman.exe Pro Edition: up to and including 2.5.1.12155
- A.k.i Software Pmman.exe Standard + IMAP4 Edition: up to and including 2.5.1.12156
- A.k.i Software Pmman.exe Standard Edition: up to and including 2.5.1.12154
- Aki Pmman.exe\/enterprise Edition\/: before 2.5.1.12158 (fixed in 2.5.1.12158)
- Aki Pmman.exe\/pro Edition\/: before 2.5.1.12155 (fixed in 2.5.1.12155)
- Aki Pmman.exe\/pro Plus IMAP4 Edition\/: before 2.5.1.12157 (fixed in 2.5.1.12157)
- Aki Pmman.exe\/standard Edition\/: before 2.5.1.12154 (fixed in 2.5.1.12154)
- Aki Pmman.exe\/standard Plus IMAP4 Edition: before 2.5.1.12156 (fixed in 2.5.1.12156)
Published 2024-03-18. Last modified 2026-06-17.