CVE-2023-40747: A.k.i Software Pmman.exe Enterprise Edition

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Directory traversal vulnerability exists in A.K.I Software's PMailServer/PMailServer2 products' CGIs included in Internal Simple Webserver. If this vulnerability is exploited, a remote attacker may access arbitrary files outside DocumentRoot.

Affected products

  • A.k.i Software Pmman.exe Enterprise Edition: up to and including 2.5.1.12158
  • A.k.i Software Pmman.exe Pro + IMAP4 Edition: up to and including 2.5.1.12157
  • A.k.i Software Pmman.exe Pro Edition: up to and including 2.5.1.12155
  • A.k.i Software Pmman.exe Standard + IMAP4 Edition: up to and including 2.5.1.12156
  • A.k.i Software Pmman.exe Standard Edition: up to and including 2.5.1.12154
  • Aki Pmman.exe\/enterprise Edition\/: before 2.5.1.12158 (fixed in 2.5.1.12158)
  • Aki Pmman.exe\/pro Edition\/: before 2.5.1.12155 (fixed in 2.5.1.12155)
  • Aki Pmman.exe\/pro Plus IMAP4 Edition\/: before 2.5.1.12157 (fixed in 2.5.1.12157)
  • Aki Pmman.exe\/standard Edition\/: before 2.5.1.12154 (fixed in 2.5.1.12154)
  • Aki Pmman.exe\/standard Plus IMAP4 Edition: before 2.5.1.12156 (fixed in 2.5.1.12156)

Published 2024-03-18. Last modified 2026-06-17.