HGiga iSherlock OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the web service of HGiga's iSherlock, specifically in versions 4.5 and 5.5, including the MailSherlock, SpamSherlock, and AuditSherlock components. This vulnerability allows unauthenticated remote attackers to inject and execute arbitrary operating system commands on the server.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server, potentially leading to a full system compromise, depending on the commands executed and the privileges of the user under which the web service runs.

Remediation

Users of iSherlock 4.5 should update the iSherlock-user-4.5 package to version 236 or later. Users of iSherlock 5.5 should update the iSherlock-user-5.5 package to version 236 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.