HGiga MailSherlock - SQL Injection -1
Description
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
HGiga MailSherlock contains a SQL injection vulnerability in a URL parameter of the email function, allowing authenticated attackers to execute unauthorized SQL commands.
Vulnerability
HGiga MailSherlock, specifically iSherlock MSR45/SSR45 with system packages iSherlock-user-4.5 below version 120 and iSherlock-antispam-4.5 below version 133, contains a SQL injection vulnerability in a URL parameter of the email function. An authenticated attacker can inject SQL syntax into the parameter, leading to unauthorized SQL command execution [1].
Exploitation
The attacker must first be logged into the MailSherlock system. After authentication, the attacker crafts a malicious URL containing SQL injection payloads in the parameter of the email function. The application does not properly sanitize the input, allowing the injected SQL commands to be processed by the database [1].
Impact
A successful SQL injection allows the attacker to execute arbitrary SQL commands, potentially leading to high confidentiality impact (reading sensitive data) and low integrity and availability impacts (modifying or deleting data) [1]. The CVSS score is 7.0 (High) [1].
Mitigation
HGiga has released fixed versions: update to system packages iSherlock-user-4.5-120.i386.rpm and iSherlock-antispam-4.5-133.i386.rpm for iSherlock MSR45/SSR45 systems [1]. No workarounds are mentioned in the reference.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- HGiga/MailSherlock MSR45/SSR45v5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.twcert.org.tw/tw/cp-132-4261-d5379-1.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.