CVE-2020-35743: Hgiga MSR45 Isherlock-Antispam

High severity, CVSS 7.6. EPSS: 0.6% chance of exploitation in the next 30 days.

HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.

Affected products

  • Hgiga MSR45 Isherlock-Antispam: before 4.5-133 (fixed in 4.5-133)
  • Hgiga MSR45 Isherlock-User: before 4.5-120 (fixed in 4.5-120)
  • Hgiga SSR45 Isherlock-Antispam: before 4.5-133 (fixed in 4.5-133)
  • Hgiga SSR45 Isherlock-User: before 4.5-120 (fixed in 4.5-120)

Published 2020-12-31. Last modified 2026-06-17.