ZeroHour

CVE-2023-24842

CVSS 3.1
5.3 medium
EPSS
<1%p46
Published
()
Modified
Description

HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL.

Vendors
hgiga
Products
oaklouds mailsherlock
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.