First published: Mon Jun 03 2019(Updated: )
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&new=hacker@socialengineering.com&new_memo=&add=%E6%96%B0%E5%A2%9E without any authorizes.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Hgiga Msr35 Isherlock-base | <1.5.328 | |
Hgiga Msr35 Isherlock-sysinfo | <1.5.196 | |
Hgiga Msr35 Isherlock-user | <1.5.127 | |
Hgiga Msr35 Isherlock-useradmin | <1.5.239 | |
Hgiga Msr45 Isherlock-base | <4.5-206 | |
Hgiga Msr45 Isherlock-sysinfo | <4.5-109 | |
Hgiga Msr45 Isherlock-user | <4.5-81 | |
Hgiga Msr45 Isherlock-useradmin | <4.5-106 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9882 is a CSRF vulnerability found in multiple modules of MailSherlock MSR35 and MSR45.
CVE-2019-9882 has a severity rating of 8.8 out of 10 (high).
CVE-2019-9882 allows attackers to add malicious email sources into the whitelist without any authentication.
CVE-2019-9882 affects the following software versions: Hgiga Msr35 Isherlock-base up to version 1.5.328, Hgiga Msr35 Isherlock-sysinfo up to version 1.5.196, Hgiga Msr35 Isherlock-user up to version 1.5.127, Hgiga Msr35 Isherlock-useradmin up to version 1.5.239, Hgiga Msr45 Isherlock-base up to version 4.5-206, Hgiga Msr45 Isherlock-sysinfo up to version 4.5-109, Hgiga Msr45 Isherlock-user up to version 4.5-81, and Hgiga Msr45 Isherlock-useradmin up to version 4.5-106.
To fix CVE-2019-9882, it is recommended to apply the latest patches and updates provided by MailSherlock.