CVE-2020-35741
31.12.2020, 08:15
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
Vendor | Product | Version |
---|---|---|
hgiga | msr45_isherlock-antispam | 𝑥 < 4.5-133 |
hgiga | msr45_isherlock-user | 𝑥 < 4.5-120 |
hgiga | ssr45_isherlock-antispam | 𝑥 < 4.5-133 |
hgiga | ssr45_isherlock-user | 𝑥 < 4.5-120 |
𝑥
= Vulnerable software versions