CVE-2020-35741
31.12.2020, 08:15
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
| Vendor | Product | Version |
|---|---|---|
| hgiga | msr45_isherlock-antispam | 𝑥 < 4.5-133 |
| hgiga | msr45_isherlock-user | 𝑥 < 4.5-120 |
| hgiga | ssr45_isherlock-antispam | 𝑥 < 4.5-133 |
| hgiga | ssr45_isherlock-user | 𝑥 < 4.5-120 |
𝑥
= Vulnerable software versions