Description
hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy files referenced in the update process, and a remote attacker could induce a user to crafted web page, causing damage such as malicious code infection.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update software over hslogin2.dll ActiveX Control 6.7.8.9002 / 7.3.4.1 version or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28742 | hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy files referenced in the update process, and a remote attacker could induce a user to crafted web page, causing damage such as malicious code infection. |
References
History
No history.
Status: PUBLISHED
Assigner: krcert
Published:
Updated: 2024-09-16T23:15:41.307Z
Reserved: 2020-01-22T00:00:00.000Z
Link: CVE-2020-7810
No data.
Status : Modified
Published: 2020-08-07T16:15:11.967
Modified: 2024-11-21T05:37:50.830
Link: CVE-2020-7810
No data.
OpenCVE Enrichment
No data.
EUVD