The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.
CVE ID: CVE-2024-4299
CVSS Base Severity: HIGH
CVSS Base Score: 7.2
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vendor: HGiga
Product: iSherlock 4.5
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 19.28% (scored less or equal to compared to others)
EPSS Date: 2025-03-14 (when was this score calculated)