References https://www.twcert.org.tw/newepaper/cp-151-8102-b94a9-3.html https://www.twcert.org.tw/tw/cp-132-8102-b94a9-1.html https://www.twcert.org.tw/tw/cp-132-7936-f6381-1.html https://www.ithome.com.tw/news/165179 https://www.cellopoint.com/post/seg-feedback-2024?lang=zh https://www.cellopoint.com/post/rce-2024 https://www.twcert.org.tw/newepaper/cp-151-7936-f6381-3.html https://www.cvedetails.com/cve/CVE-2024-6744/ https://www.cvedetails.com/cve/CVE-2024-9043/ https://vuldb.com/vuln/278213 https://gbhackers.com/cellopoint-secure-email-gateway-flaw/
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2015-7501: Red Hat JBoss - Insecure DeserializationPoCCVE-2019-1003030: Jenkins Pipeline Groovy Plugin <=2.63 - Insecure Deserialization英華達|全家寶 Cloud - Insecure Direct Object Reference云连ERP管理系统 /gateway/download!download.action 代码执行漏洞广联达OA /Mail/Services/EmailAccountOrgUserService.asmx/GetUserEmailByOrgEmails XML 外部实体注入漏洞PoCCVE-2021-24916: WordPress Qubely < 1.8.6 - Unauthenticated Email SendingPoCCVE-2023-7327: Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File ReadPoCCVE-2026-46725: TYPO3 ceselector Extension - Insecure Deserialization沛盛資訊|OMICARD EDM - Insecure Direct Object Reference金財通商務科技|Service Center - Insecure Direct Object ReferenceSecurePoint UTM /spcgi.cgi 信息泄露漏洞(CVE-2023-22620)PoCapache-casbin-mcp-gateway-default-login: Apache Casbin MCP Gateway - Default Login