OS Command Injection Vulnerability in iSherlock by HGiga
CVE-2025-11900
9.3CRITICAL
What is CVE-2025-11900?
The iSherlock application developed by HGiga is vulnerable to an OS Command Injection issue, enabling unauthenticated remote attackers to execute arbitrary operating system commands. This flaw can be exploited by sending specially crafted requests to the server, compromising its security and potentially leading to unauthorized access and control over the affected system. Users of iSherlock are urged to review their configurations and apply necessary security measures to mitigate this vulnerability.
Affected Version(s)
iSherlock 4.5 0 < 774
iSherlock 4.5 0 < 440
iSherlock 5.5 0 < 774