CVE-2023-24842: HGiga MailSherlock - Broken Access Control
HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24842?
CVE-2023-24842 is considered a high-severity vulnerability due to its potential for unauthorized access to sensitive email content.
How do I fix CVE-2023-24842?
To fix CVE-2023-24842, ensure that proper access controls are implemented and validated for user IDs and mail IDs in the application.
Who is affected by CVE-2023-24842?
Users of HGiga OAKlouds MailSherlock version 4.5 are affected by CVE-2023-24842.
What type of attack does CVE-2023-24842 enable?
CVE-2023-24842 enables unauthorized users to access partial content of other users' emails, posing a privacy risk.
Can CVE-2023-24842 be exploited remotely?
Yes, CVE-2023-24842 can be exploited by unauthenticated remote users.