CVE-2020-35743: Hgiga MSR45 Isherlock-Antispam
High severity, CVSS 7.6. EPSS: 0.6% chance of exploitation in the next 30 days.
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
Affected products
- Hgiga MSR45 Isherlock-Antispam: before 4.5-133 (fixed in 4.5-133)
- Hgiga MSR45 Isherlock-User: before 4.5-120 (fixed in 4.5-120)
- Hgiga SSR45 Isherlock-Antispam: before 4.5-133 (fixed in 4.5-133)
- Hgiga SSR45 Isherlock-User: before 4.5-120 (fixed in 4.5-120)
Published 2020-12-31. Last modified 2026-06-17.