PT-2026-41706 · Unknown · Hc Mailinspector

Published

2026-05-18

·

Updated

2026-05-18

·

CVE-2026-29963

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HSC MailInspector version 5.3.3-7
Description Improper validation of user-supplied input in the '/tap/dw.php' endpoint allows a remote attacker to access arbitrary files on the underlying operating system, leading to unauthorized disclosure of sensitive information. This occurs because the text parameter is used to construct file paths without adequate normalization or restriction to a safe base directory. Path Traversal is a flaw where an attacker can access files and directories that are stored outside the web root folder.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the text parameter in the '/tap/dw.php' endpoint until the issue is resolved.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29963

Affected Products

Hc Mailinspector