← back
CVE-2020-25850high

HGiga MailSherlock - Arbitrary File Download

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 1.1%
exploitation probability
1.1%top 37% of all CVEs
observed exploitation
nono source reports it
The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H