CVE-2023-24840: HGiga MailSherlock - SQL Injection
Published Mar 27, 2023
·Updated
HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database.
Affected Software
1 affected component
Hgiga Oaklouds Mailsherlock=4.5
Remediation
Information
Update MailSherlock package version to iSherlock-query-4.5-168.386
Event History
Mar 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for HGiga MailSherlock?
The vulnerability ID for HGiga MailSherlock is CVE-2023-24840.
2
What is the severity rating for CVE-2023-24840?
The severity rating for CVE-2023-24840 is high (7.2).
3
What is the affected software for CVE-2023-24840?
The affected software for CVE-2023-24840 is Hgiga Oaklouds Mailsherlock version 4.5.
4
What is the CWE category for CVE-2023-24840?
The CWE category for CVE-2023-24840 is CWE-89 (SQL Injection).
5
How can an attacker exploit CVE-2023-24840?
An authenticated remote attacker with administrator privilege can exploit CVE-2023-24840 to inject SQL commands and perform unauthorized actions on the database.