CVE-2023-4595: Seattlelab Slmail
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.
Affected products
- Seattlelab Slmail: version 5.5.0.4433 only
Published 2023-11-23. Last modified 2026-06-17.