nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-24839 CVE-2023-24839
MEDIUM
HGiga MailSherlock - Reflected XSS
Record summary
CVE-2023-24839 has a selected CVSS score of 6.1 (medium).
Description
HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript, conducting a reflected XSS attack.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MailSherlockBrowse HGiga / MailSherlock | CVE List | iSherlock-user-4.5 to ≤ iSherlock-user-4.5-161 | affected |
| iSherlock-antispam-4.5 to ≤ iSherlock-antispam-4.5-167 | affected |
References
2twcert.org.tw
https://www.twcert.org.tw/tw/cp-132-6958-e1a8e-1.html