Description
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.
No analysis available yet.
Remediation
Vendor Solution
Update iSherlock-sysinfo-4.5 to version 147 or later Update iSherlock-sysinfo-5.5 to version 147 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32847 | The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7767-ce3b4-1.html |
|
History
Mon, 26 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hgiga:isherlock:*:*:*:*:*:*:*:* |
Mon, 14 Jul 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hgiga
Hgiga isherlock |
|
| CPEs | cpe:2.3:a:hgiga:isherlock:4.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Hgiga
Hgiga isherlock |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-07-14T02:17:55.601Z
Reserved: 2024-04-29T01:47:07.589Z
Link: CVE-2024-4297
Updated: 2024-08-01T20:33:53.076Z
Status : Analyzed
Published: 2024-04-29T03:15:09.613
Modified: 2026-01-26T14:42:44.507
Link: CVE-2024-4297
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD