HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-6959-cdecb-1.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2023-03-27T00:00:00
Updated: 2024-08-02T11:03:19.290Z
Reserved: 2023-01-31T00:00:00
Link: CVE-2023-24840
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-27T04:15:10.087
Modified: 2024-11-21T07:48:30.080
Link: CVE-2023-24840
Redhat
No data.