OS Command Injection Vulnerability in iSherlock by Hgiga
CVE-2025-7451

9.3CRITICAL

Key Information:

Vendor

Hgiga

Vendor
CVE Published:
14 July 2025

What is CVE-2025-7451?

An OS Command Injection vulnerability in iSherlock, developed by Hgiga, allows unauthenticated remote attackers to inject and execute arbitrary OS commands on affected servers. This exploit can lead to severe security breaches, making it imperative for users to update their systems immediately to mitigate potential risks. Failure to apply the necessary updates may result in unauthorized access and control over the vulnerable servers.

Affected Version(s)

iSherlock-maillog-4.5 0 < 137

iSherlock-maillog-5.5 0 < 137

iSherlock-smtp-4.5 0 < 732

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7451 : OS Command Injection Vulnerability in iSherlock by Hgiga