HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2023-03-27T00:00:00

Updated: 2024-08-02T11:03:19.290Z

Reserved: 2023-01-31T00:00:00

Link: CVE-2023-24840

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-03-27T04:15:10.087

Modified: 2023-03-30T17:56:58.790

Link: CVE-2023-24840

cve-icon Redhat

No data.