CVE-2018-17542
11.02.2019, 20:29
SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request.
Vendor | Product | Version |
---|---|---|
hgiga | oaklouds_mailsherlock | 𝑥 < 1.5.235 |
𝑥
= Vulnerable software versions
References