Skip to main content

Vendor archive

hgiga CVEs

Beta · best-effort

34 CVEs tagged to vendor hgiga10 Critical, 17 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-2150

Published Mar 10, 2025

The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4299

Published Apr 29, 2024

The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allow…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4298

Published Apr 29, 2024

The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remo…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4297

Published Apr 29, 2024

The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allo…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4296

Published Apr 29, 2024

The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowi…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37292

Published Jul 21, 2023

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iShe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-25909

Published Mar 27, 2023

HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run ar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24842

Published Mar 27, 2023

HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24841

Published Mar 27, 2023

HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege ca…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24840

Published Mar 27, 2023

HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24839

Published Mar 27, 2023

HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript, conductin…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38118

Published Aug 30, 2022

OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delet…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37913

Published Sep 15, 2021

The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote attackers can use this vulnera…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-37912

Published Sep 15, 2021

The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remote attackers can use this vuln…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-22852

Published Jan 19, 2021

HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22851

Published Jan 19, 2021

HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-22850

Published Jan 19, 2021

HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 34 CVEsPage 1 of 2