CVE-2020-25850: HGiga MailSherlock - Arbitrary File Download
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-25850?
CVE-2020-25850 is a vulnerability that allows remote attackers to download arbitrary system files by exploiting the 'view the source code' function of HGiga MailSherlock.
What is the severity level of CVE-2020-25850?
The severity level of CVE-2020-25850 is high, with a CVSS score of 7.5.
How does CVE-2020-25850 affect HGiga MailSherlock?
CVE-2020-25850 affects HGiga MailSherlock versions up to and excluding 4.5-117. The vulnerability allows remote attackers to exploit the 'view the source code' function and download arbitrary system files.
How can I fix CVE-2020-25850?
To fix CVE-2020-25850, it is recommended to update HGiga MailSherlock to a version higher than 4.5-117 or apply any patches or security fixes provided by the vendor.
Where can I find more information about CVE-2020-25850?
More information about CVE-2020-25850 can be found at the following reference: [link](https://www.twcert.org.tw/tw/cp-132-4258-0a8a0-1.html)