SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, which allows remote attackers to execute arbitrary code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.033
EPSS Ranking 86.5%