First published: Thu Dec 31 2020(Updated: )
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Hgiga Msr45 Isherlock-user | <4.5-117 | |
Hgiga Ssr45 Isherlock-user | <4.5-117 |
Update MailSherlock MSR45/SSR45 Module to iSherlock-user-4.5-117.i386.rpm
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25850 is a vulnerability that allows remote attackers to download arbitrary system files by exploiting the 'view the source code' function of HGiga MailSherlock.
The severity level of CVE-2020-25850 is high, with a CVSS score of 7.5.
CVE-2020-25850 affects HGiga MailSherlock versions up to and excluding 4.5-117. The vulnerability allows remote attackers to exploit the 'view the source code' function and download arbitrary system files.
To fix CVE-2020-25850, it is recommended to update HGiga MailSherlock to a version higher than 4.5-117 or apply any patches or security fixes provided by the vendor.
More information about CVE-2020-25850 can be found at the following reference: [link](https://www.twcert.org.tw/tw/cp-132-4258-0a8a0-1.html)