Please, if you suspect a vulnerability in any SME Server package, address them to security@contribs.org as all emails will receive a reply from the security team. It also allows us to ensure that the issues raised are tracked until completion.
Raising the issue in the forum tends to lead to the answer being lost.