CVE Vulnerabilities

CVE-2020-25850

Published: Dec 31, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.

Affected Software

NameVendorStart VersionEnd Version
Msr45_isherlock-userHgiga*4.5-117 (excluding)
Ssr45_isherlock-userHgiga*4.5-117 (excluding)

References