Description
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
No analysis available yet.
Remediation
Vendor Solution
Update MailSherlock MSR45/SSR45 Module to: iSherlock-user-4.5-120.i386.rpm iSherlock-antispam-4.5-133.i386.rpm
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-23397 | HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4260-ba376-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T22:55:57.902Z
Reserved: 2020-12-28T00:00:00.000Z
Link: CVE-2020-35741
No data.
Status : Modified
Published: 2020-12-31T08:15:13.660
Modified: 2024-11-21T05:27:59.487
Link: CVE-2020-35741
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD