CVE-2020-35851

HIGH

HGiga MailSherlock < 4.5-115 - OS Command Injection

Title source: llm
STIX 2.1

Description

HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/en/cp-139-4264-f10f4-2.html

Scores

CVSS v3 8.1
EPSS 0.0174
EPSS Percentile 74.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
hgiga/msr45_isherlock-user < 4.5-115
hgiga/ssr45_isherlock-user < 4.5-115
Published Dec 31, 2020
Tracked Since Feb 18, 2026