Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-8741

30
FAUCET Score

CVE-2018-8741 is a directory traversal vulnerability in SquirrelMail 1.4.22, affecting Debian Linux and SquirrelMail installations. An authenticated attacker can exploit this flaw to exfiltrate, delete, or modify files on the hosting server. With a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.4.22CPE matchmatch criteria
cpe:2.3:a:squirrelmail:squirrelmail:1.4.22:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.8HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
4.29%
Probability of exploitation in next 30 days
EPSS Percentile
90.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0429 is in the 90th percentile among its peer group of 17,808 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: squirrelmail

Vendor Advisories (1)

redhatCVE-2018-8741Important

SquirrelMail: Directory traversal flaw in Deliver.class.php can allow a remote attacker to retrieve or delete arbitrary files

Mar 15, 2018

References

gist.github.com / hannob/3c4f86863c418930ad08853c1109364e
PatchThird Party Advisory
insinuator.net / 2018/03/squirrelmail-full-disclosure-troopers18
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2018/04/msg00012.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CVXTYMZ35IC5KPNMAE6BWAQWURMX7KZO
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/T5FP5O562A4FM5TCFNEW73SS6PZONSAC
paste.pound-python.org / show/OjSLiFTxiBrTk63jqEUu
Third Party Advisory
debian.org / security/2018/dsa-4168
Third Party Advisory
openwall.com / lists/oss-security/2018/03/17/2
Mailing ListThird Party Advisory
securitytracker.com / id/1040554
Third Party AdvisoryVDB Entry