go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

HGiga iSherlock - OS Command Injection

TVN ID TVN-202504001
CVE ID CVE-2025-3361
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Affected Products:
  • iSherlock 4.5, iSherlock 5.5 (including MailSherlock, SpamSherlock, AuditSherlock)
Affected Packages:
  • iSherlock-user-4.5: before version 236
  • iSherlock-user-5.5: before version 236
Description The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
Solution For iSherlock 4.5, please update package iSherlock-user-4.5 to version 236 or later.
For iSherlock 5.5, please update package iSherlock-user-5.5 to version 236 or later.
Credit Fi Liu(CHT Security)
Public Date 2025-04-07
Top