Vulnerability Description
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hgiga | Msr45 Isherlock-User | < 4.5-117 |
| Hgiga | Ssr45 Isherlock-User | < 4.5-117 |
References
- https://www.twcert.org.tw/tw/cp-132-4258-0a8a0-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4258-0a8a0-1.htmlThird Party Advisory
FAQ
What is CVE-2020-25850?
CVE-2020-25850 is a vulnerability with a CVSS score of 8.1 (HIGH). The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
How severe is CVE-2020-25850?
CVE-2020-25850 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-25850?
Check the references section above for vendor advisories and patch information. Affected products include: Hgiga Msr45 Isherlock-User, Hgiga Ssr45 Isherlock-User.