HGiga MailSherlock - SQL Injection
CVE-2023-24840
7.2HIGH
What is CVE-2023-24840?
The HGiga MailSherlock product is susceptible to SQL injection due to insufficient validation of user input in its mail query function. This vulnerability can be exploited by an authenticated remote attacker with administrator privileges, allowing them to inject malicious SQL commands. As a result, the attacker may gain unauthorized access to read, modify, or delete database contents, potentially compromising sensitive information and affecting the integrity of the system.
Affected Version(s)
MailSherlock iSherlock-query-4.5
