8.1
CVE-2020-25850
- EPSS 0.36%
- Veröffentlicht 31.12.2020 08:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:54
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hgiga ≫ Msr45 Isherlock-user Version < 4.5-117
Hgiga ≫ Ssr45 Isherlock-user Version < 4.5-117
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.552 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| twcert@cert.org.tw | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|