go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

HGiga|iSherlock - OS Command Injection

TVN ID TVN-202510005
CVE ID CVE-2025-11900
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Affected product:
iSherlock 4.5 and iSherlock 5.5 (including MailSherlock, SpamSherlock, AuditSherlock)

Affected package:
iSherlock-smtp-4.5: before version 774
iSherlock-smtp-5.5: before version 774
iSherlock-base-4.5: before version 440
iSherlock-base-5.5: before version 440
Description The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
Solution Update iSherlock-smtp-4.5 package to version 774 and later
Update iSherlock-smtp-5.5 package to version 774 and later
Update iSherlock-base-4.5 package to version 440 and later
Update iSherlock-base-5.5 package to version 440 and later
Credit Ting-Wei Hsieh (CHT Security)
Public Date 2025-10-17
Top