CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 80.9%