HGiga MailSherlock - Broken Access Control
Description
HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated access to partial email content in HGiga MailSherlock via insufficient access control in URL parameters.
Vulnerability
HGiga MailSherlock versions with iSherlock-user-4.5 <= 4.5-161 and iSherlock-antispam-4.5 <= 4.5-167 contain an insufficient access control vulnerability [1]. An unauthenticated remote user can exploit this bug to view partial content (e.g., email subject) of another user's mail by manipulating the user ID and mail ID parameters in the URL [1].
Exploitation
An unauthenticated remote attacker can directly craft HTTP requests to the MailSherlock web interface, changing the user ID and mail ID within the URL [1]. No prior authentication or user interaction is required; the attacker only needs network access to the vulnerable system [1].
Impact
Successful exploitation allows an attacker to read partial email content (specifically the subject line) of other users, leading to information disclosure with low confidentiality impact [1]. The attacker does not gain write access or full message body access, and the integrity and availability of the system remain unaffected.
Mitigation
The vendor released fixed packages on 2023-02-24: iSherlock-user-4.5-162.386.rpm and iSherlock-antispam-4.5-168.386.rpm [1]. Users should update these system components to the patched versions. There are no known workarounds; applying the update is the only recommended mitigation.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- HGiga/MailSherlockv5Range: iSherlock-user-4.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.