← back
CVE-2021-26608

handysoft groupware arbitrary file download and execution vulnerability

CVSS 8.8 HIGHEPSS 0.6%CWE-353
An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
handysoft · HShell.dll

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →