HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-6961-12444-1.html |
|
History
Wed, 19 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published: 2023-03-27T00:00:00.000Z
Updated: 2025-02-19T15:54:06.404Z
Reserved: 2023-01-31T00:00:00.000Z
Link: CVE-2023-24842
Updated: 2024-08-02T11:03:19.354Z
Status : Modified
Published: 2023-03-27T04:15:10.247
Modified: 2024-11-21T07:48:30.320
Link: CVE-2023-24842
No data.
ReportizFlow