Squirrelmail 1.4.22 is affected by a Remote Code Execution flaw, no fix is available

April 25, 2017

The popular PHP webmail package SquirrelMail is affected by a remote code execution vulnerability tracked as CVE-2017-7692, that could be exploited by hackers to execute arbitrary commands on the target and fully control it.