Skip to main content

Vendor/product archive

hgiga / msr45_isherlock-user CVEs

Beta · best-effort

10 CVEs tagged to hgiga / msr45_isherlock-user1 Critical, 9 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2020-25848

Published Dec 31, 2020

HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.

CVSS 9.8 · Critical

CVE-2019-9883

Published Jun 3, 2019

Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=fu…

CVSS 8.8 · High

CVE-2019-9882

Published Jun 3, 2019

Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=em…

CVSS 8.8 · High
Showing 1-10 of 10 CVEsPage 1 of 1