The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.
History

Mon, 14 Jul 2025 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Hgiga
Hgiga isherlock
CPEs cpe:2.3:a:hgiga:isherlock:4.5:*:*:*:*:*:*:*
cpe:2.3:a:hgiga:isherlock:5.5:*:*:*:*:*:*:*
Vendors & Products Hgiga
Hgiga isherlock
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2025-07-14T02:19:23.281Z

Reserved: 2024-04-29T01:47:09.033Z

Link: CVE-2024-4298

cve-icon Vulnrichment

Updated: 2024-08-01T20:33:53.107Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-29T03:15:09.810

Modified: 2024-11-21T09:42:34.200

Link: CVE-2024-4298

cve-icon Redhat

No data.