CVE-2023-24841
HGiga MailSherlock - Command Injection
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
27 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
HGiga · MailSherlockWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →