PT-2020-17411 · Hgiga · Mailsherlock

Dio Lin

+1

·

Published

2020-12-31

·

Updated

2021-01-08

·

CVE-2020-35741

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions HGiga MailSherlock (affected versions not specified)
Description The issue concerns the lack of validation for user parameters on multiple login pages, allowing attackers to inject JavaScript syntax for cross-site scripting (XSS) attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35741

Affected Products

Mailsherlock