CVE-2018-17542

MEDIUM

MailSherlock <1.5.235 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request.

References (2)

Core 2

Scores

CVSS v3 4.3
EPSS 0.0123
EPSS Percentile 65.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
hgiga/oaklouds_mailsherlock < 1.5.235
Published Feb 11, 2019
Tracked Since Feb 18, 2026