CVE-2024-2590: Amss++ Project Amss++

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/mail/main/select_send.php, in the 'sd_index' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

Affected products

Published 2024-03-18. Last modified 2026-06-17.