Description
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.
No analysis available yet.
Remediation
Vendor Solution
Update iSherlock-sysinfo-4.5 to version 147 or later Update iSherlock-sysinfo-5.5 to version 147 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32849 | The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands. |
References
History
Mon, 26 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hgiga:isherlock:*:*:*:*:*:*:*:* |
Fri, 14 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hgiga
Hgiga isherlock |
|
| CPEs | cpe:2.3:a:hgiga:isherlock:4.5:*:*:*:*:*:*:* cpe:2.3:a:hgiga:isherlock:5.5:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hgiga
Hgiga isherlock |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-07-14T02:21:35.775Z
Reserved: 2024-04-29T01:47:10.212Z
Link: CVE-2024-4299
Updated: 2024-08-01T20:33:53.021Z
Status : Analyzed
Published: 2024-04-29T04:15:08.623
Modified: 2026-01-26T14:27:50.970
Link: CVE-2024-4299
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD