HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Msr45_isherlock-antispam | Hgiga | * | 4.5-130 (excluding) |
Msr45_isherlock-audit | Hgiga | * | 4.5-143 (excluding) |
Msr45_isherlock-base | Hgiga | * | 4.5-243 (excluding) |
Msr45_isherlock-user | Hgiga | * | 4.5-114 (excluding) |
Msr45_isherlock-useradmin | Hgiga | * | 4.5-122 (excluding) |
Ssr45_isherlock-antispam | Hgiga | * | 4.5-130 (excluding) |
Ssr45_isherlock-audit | Hgiga | * | 4.5-143 (excluding) |
Ssr45_isherlock-base | Hgiga | * | 4.5-243 (excluding) |
Ssr45_isherlock-user | Hgiga | * | 4.5-114 (excluding) |
Ssr45_isherlock-useradmin | Hgiga | * | 4.5-112 (excluding) |