PT-2024-24537 · Hsc Cybersecurity · Hc Mailinspector
Chucrutis
·
Published
2024-05-06
·
Updated
2024-07-03
·
CVE-2024-32369
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HSC Cybersecurity HC Mailinspector versions 5.2.17-3 through 5.2.18
Description
The issue allows a remote attacker to obtain sensitive information via a crafted payload to the
start and limit parameters in the "mliWhiteList.php" component. This enables the attacker to extract data by manipulating these parameters.Recommendations
For HSC Cybersecurity HC Mailinspector versions 5.2.17-3 through 5.2.18, consider restricting access to the "mliWhiteList.php" component until a patch is available. As a temporary workaround, avoid using the
start and limit parameters in the affected component to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hc Mailinspector