CVE-2024-4298: HGiga iSherlock - Command Injection
The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
iSherlock-query-4.5to a version that resolves this vulnerability.Fixed in 188 - Upgrade
Upgrade
iSherlock-query-5.5to a version that resolves this vulnerability.Fixed in 188
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4298?
CVE-2024-4298 is classified as a high-severity vulnerability due to its potential for command injection attacks.
How do I fix CVE-2024-4298?
To fix CVE-2024-4298, ensure that proper input validation and sanitization are implemented in the email search interface.
What types of attacks can exploit CVE-2024-4298?
CVE-2024-4298 can be exploited for command injection attacks by remote attackers with administrative privileges.
Which software is affected by CVE-2024-4298?
CVE-2024-4298 affects HGiga iSherlock, including its components MailSherlock, SpamSherock, and AuditSherlock.
Who can exploit CVE-2024-4298?
Only remote attackers with administrative privileges can exploit CVE-2024-4298 due to its access requirements.