CVE-2023-24841: HGiga MailSherlock - Command Injection
HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-24841?
CVE-2023-24841 is a vulnerability in the HGiga MailSherlock query function for connection log, which has insufficient filtering for user input.
How does CVE-2023-24841 affect HGiga MailSherlock?
CVE-2023-24841 affects HGiga MailSherlock version 4.5, allowing an authenticated remote attacker with administrator privilege to inject and execute arbitrary system commands.
What is the severity of CVE-2023-24841?
CVE-2023-24841 has a severity rating of 7.2 (high).
How can an attacker exploit CVE-2023-24841?
An authenticated remote attacker with administrator privilege can exploit CVE-2023-24841 by injecting and executing arbitrary system commands.
Is there a fix for CVE-2023-24841?
At the moment, there is no known fix for CVE-2023-24841. It is recommended to follow the recommendations provided by the vendor or security advisories.