VYPR
Unrated severityNVD Advisory· Published Dec 31, 2020· Updated Sep 16, 2024

HGiga MailSherlock - SQL Injection -1

CVE-2020-35742

Description

HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

HGiga MailSherlock contains a SQL injection vulnerability in a URL parameter of the email function, allowing authenticated attackers to execute unauthorized SQL commands.

Vulnerability

HGiga MailSherlock, specifically iSherlock MSR45/SSR45 with system packages iSherlock-user-4.5 below version 120 and iSherlock-antispam-4.5 below version 133, contains a SQL injection vulnerability in a URL parameter of the email function. An authenticated attacker can inject SQL syntax into the parameter, leading to unauthorized SQL command execution [1].

Exploitation

The attacker must first be logged into the MailSherlock system. After authentication, the attacker crafts a malicious URL containing SQL injection payloads in the parameter of the email function. The application does not properly sanitize the input, allowing the injected SQL commands to be processed by the database [1].

Impact

A successful SQL injection allows the attacker to execute arbitrary SQL commands, potentially leading to high confidentiality impact (reading sensitive data) and low integrity and availability impacts (modifying or deleting data) [1]. The CVSS score is 7.0 (High) [1].

Mitigation

HGiga has released fixed versions: update to system packages iSherlock-user-4.5-120.i386.rpm and iSherlock-antispam-4.5-133.i386.rpm for iSherlock MSR45/SSR45 systems [1]. No workarounds are mentioned in the reference.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.