Description
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update MailSherlock MSR45/SSR45 Module to: iSherlock-user-4.5-120.i386.rpm iSherlock-antispam-4.5-133.i386.rpm
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-23396 | HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4259-90f23-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T23:36:40.227Z
Reserved: 2020-12-28T00:00:00.000Z
Link: CVE-2020-35740
No data.
Status : Modified
Published: 2020-12-31T08:15:13.550
Modified: 2024-11-21T05:27:59.320
Link: CVE-2020-35740
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD