CVE-2020-25848

CRITICAL WAF: Low
CVSS 9.8 Published: 2020-12-31
CWE-287

HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
hgigamsr45_isherlock-antispamup to 4.5-130
hgigamsr45_isherlock-auditup to 4.5-143
hgigamsr45_isherlock-baseup to 4.5-243
hgigamsr45_isherlock-userup to 4.5-114
hgigamsr45_isherlock-useradminup to 4.5-122
hgigassr45_isherlock-antispamup to 4.5-130
hgigassr45_isherlock-auditup to 4.5-143
hgigassr45_isherlock-baseup to 4.5-243
hgigassr45_isherlock-userup to 4.5-114
hgigassr45_isherlock-useradminup to 4.5-112

References

Back to CVE Database