CVE-2023-37292: Hgiga Isherlock

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Injection.This issue affects iSherlock 4.5: before iSherlock-user-4.5-174; iSherlock 5.5: before iSherlock-user-5.5-174.

Affected products

  • Hgiga Isherlock: from 4.5, before 4.5-174 (fixed in 4.5-174); from 5.5, before 5.5-174 (fixed in 5.5-174)

Published 2023-07-21. Last modified 2026-06-17.