CVE Vulnerabilities

CVE-2020-25850

Published: Dec 31, 2020 | Modified: Jan 08, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.

Affected Software

Name Vendor Start Version End Version
Msr45_isherlock-user Hgiga * 4.5-117 (excluding)
Ssr45_isherlock-user Hgiga * 4.5-117 (excluding)

References