PT-2026-41706 · Unknown · Hc Mailinspector
Published
2026-05-18
·
Updated
2026-05-18
·
CVE-2026-29963
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HSC MailInspector version 5.3.3-7
Description
Improper validation of user-supplied input in the '/tap/dw.php' endpoint allows a remote attacker to access arbitrary files on the underlying operating system, leading to unauthorized disclosure of sensitive information. This occurs because the
text parameter is used to construct file paths without adequate normalization or restriction to a safe base directory. Path Traversal is a flaw where an attacker can access files and directories that are stored outside the web root folder.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
text parameter in the '/tap/dw.php' endpoint until the issue is resolved.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hc Mailinspector