HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-28830 | HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database. |
Fixes
Solution
Update MailSherlock package version to iSherlock-query-4.5-168.386
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-6959-cdecb-1.html |
|
History
Wed, 19 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-02-19T15:56:20.875Z
Reserved: 2023-01-31T00:00:00.000Z
Link: CVE-2023-24840
Updated: 2024-08-02T11:03:19.290Z
Status : Modified
Published: 2023-03-27T04:15:10.087
Modified: 2024-11-21T07:48:30.080
Link: CVE-2023-24840
No data.
OpenCVE Enrichment
No data.
EUVD