PT-2024-24540 · Hsc Cybersecurity · Hc Mailinspector

Chucrutis

·

Published

2024-05-06

·

Updated

2024-07-03

·

CVE-2024-32371

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HSC Cybersecurity HC Mailinspector versions 5.2.17-3 through 5.2.18
Description The issue allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0.
Recommendations For versions 5.2.17-3 through 5.2.18, consider restricting access to the parameter type to prevent privilege escalation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-32371

Affected Products

Hc Mailinspector