Description
SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update the software to the latest version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-9295 | SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request. |
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T18:54:20.899Z
Reserved: 2018-09-26T00:00:00.000Z
Link: CVE-2018-17542
No data.
Status : Modified
Published: 2019-02-11T20:29:00.443
Modified: 2024-11-21T03:54:35.057
Link: CVE-2018-17542
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD