CVE-2020-35740: Hgiga MSR45 Isherlock-Antispam

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.

Affected products

  • Hgiga MSR45 Isherlock-Antispam: before 4.5-133 (fixed in 4.5-133)
  • Hgiga MSR45 Isherlock-User: before 4.5-120 (fixed in 4.5-120)
  • Hgiga SSR45 Isherlock-Antispam: before 4.5-133 (fixed in 4.5-133)
  • Hgiga SSR45 Isherlock-User: before 4.5-120 (fixed in 4.5-120)

Published 2020-12-31. Last modified 2026-06-17.