hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy files referenced in the update process, and a remote attacker could induce a user to crafted web page, causing damage such as malicious code infection.

Project Subscriptions

Vendors Products
Handysoft Subscribe
Hslogin2.dll Subscribe
Microsoft Subscribe
Windows Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-28742 hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy files referenced in the update process, and a remote attacker could induce a user to crafted web page, causing damage such as malicious code infection.
Fixes

Solution

Update software over hslogin2.dll ActiveX Control 6.7.8.9002 / 7.3.4.1 version or higher.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: krcert

Published:

Updated: 2024-09-16T23:15:41.307Z

Reserved: 2020-01-22T00:00:00

Link: CVE-2020-7810

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-08-07T16:15:11.967

Modified: 2024-11-21T05:37:50.830

Link: CVE-2020-7810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses