Skip to main content

Vendor/product archive

hgiga / oaklouds_mailsherlock CVEs

Beta · best-effort

5 CVEs tagged to hgiga / oaklouds_mailsherlock0 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2023-24842

Published Mar 27, 2023

HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24841

Published Mar 27, 2023

HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege ca…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24840

Published Mar 27, 2023

HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24839

Published Mar 27, 2023

HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript, conductin…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17542

Published Feb 11, 2019

SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1