Back to Database
Status published
High
CVE-2023-24840
HGiga MailSherlock - SQL Injection
Vulnerability Description
HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-24840
Credits & Attribution
No credits recorded in the NVD database.
More from HGiga
View All →CVE-2025-3364
HGiga PowerStation - Chroot Escape
Medium
6.7
CVE-2025-3363
HGiga iSherlock - OS Command Injection
Critical
9.8
CVE-2025-3362
HGiga iSherlock - OS Command Injection
Critical
9.8
CVE-2025-3361
HGiga iSherlock - OS Command Injection
Critical
9.8
CVE-2025-2150
HGiga C&Cm@il - Stored Cross-Site Scripting
Medium
5.4
Affected Vendor
HGiga
View all reports →Affected Software
MailSherlock
Vulnerable Versions:
iSherlock-query-4.5
Timeline
Official Publish:
March 27th, 2023
Last Modified:
February 19th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H