Back to Database
Status published
Medium
CVE-2023-24842
HGiga MailSherlock - Broken Access Control
Vulnerability Description
HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-24842
Credits & Attribution
No credits recorded in the NVD database.
More from HGiga
View All →CVE-2025-3364
HGiga PowerStation - Chroot Escape
Medium
6.7
CVE-2025-3363
HGiga iSherlock - OS Command Injection
Critical
9.8
CVE-2025-3362
HGiga iSherlock - OS Command Injection
Critical
9.8
CVE-2025-3361
HGiga iSherlock - OS Command Injection
Critical
9.8
CVE-2025-2150
HGiga C&Cm@il - Stored Cross-Site Scripting
Medium
5.4
Affected Vendor
HGiga
View all reports →Affected Software
MailSherlock
Vulnerable Versions:
iSherlock-user-4.5, iSherlock-antispam-4.5
Timeline
Official Publish:
March 27th, 2023
Last Modified:
February 19th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N