Skip to content

PRP: SmarterMail CVE-2025-52691 Pre-Auth RCE #779

@learningat2002

Description

@learningat2002
  • Identifier of the vulnerability: CVE-2025-52691

  • Affected software: SmarterTools SmarterMail

  • Type of vulnerability: Pre-Authentication Remote Code Execution (Arbitrary File Write → RCE)

  • Requires authentication: No

  • Language you would use for writing the plugin: Templated plugins (sufficient, as the vulnerability is triggered through a deterministic HTTP request and does not require complex logic beyond request construction and response validation)

  • Resources:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions