CVE-2020-35742

HIGH WAF: High
CVSS 7.6 Published: 2020-12-31
CWE-89 CWE-89

HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.

WAF Coverage Analysis

SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection
SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection

Affected Software

VendorProductVersion
hgigamsr45_isherlock-antispamup to 4.5-133
hgigamsr45_isherlock-userup to 4.5-120
hgigassr45_isherlock-antispamup to 4.5-133
hgigassr45_isherlock-userup to 4.5-120

References

Back to CVE Database