CVE-2021-22848: HGiga MailSherlock - SQL Injection-2

Published Mar 18, 2021
·
Updated

HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.

Affected Software

4 affected components
Hgiga Msr45 Isherlock-antispam<4.5-133
Hgiga Msr45 Isherlock-user<4.5-120
Hgiga Ssr45 Isherlock-antispam<4.5-133
Hgiga Ssr45 Isherlock-user<4.5-120

Remediation

Information

MailSherlock MSR45/SSR45 Module: iSherlock-user-4.5-120.i386.rpm and iSherlock-antispam-4.5-133.i386.rpm

Event History

Mar 18, 2021
CVE Published
via MITRE·04:35 AM
Data Sourced
via MITRE·04:35 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2021-22848?

CVE-2021-22848 is considered a high-severity vulnerability due to its potential for SQL injection and unauthorized access to databases.

2

How does CVE-2021-22848 allow SQL Injection?

CVE-2021-22848 allows SQL injection by enabling remote attackers to inject SQL commands through URL parameters in email pages.

3

Which software is affected by CVE-2021-22848?

CVE-2021-22848 affects multiple versions of Hgiga Msr45 Isherlock-antispam and user components before specific versions.

4

How can I mitigate the risks associated with CVE-2021-22848?

Mitigation for CVE-2021-22848 includes validating and sanitizing user input to prevent SQL injection attacks.

5

What are the consequences of exploiting CVE-2021-22848?

Exploiting CVE-2021-22848 can lead to unauthorized access to sensitive data and potential data breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203