CVE-2024-4299 HIGH

CVE-2024-4299: HGiga iSherlock - Command Injection

Vendor Hgiga
Product iSherlock 4.5
Weakness CWE-78
Published April 29, 2024
Last update July 14, 2025

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.

Key dates

02Disclosure timeline

April 29, 2024 CVE published
July 14, 2025 Record updated