ZeroHour

CVE-2020-35851

CVSS 3.1
9.8 critical
EPSS
2%p76
Published
()
Modified
Description

HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.

Vendors
hgiga
Products
msr45 isherlock-user, ssr45 isherlock-user
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.