SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request.
References
Link | Resource |
---|---|
https://twcert.org.tw/subpages/ServeThePublic/public_document_details.aspx?id=73 | Third Party Advisory |
https://twcert.org.tw/subpages/ServeThePublic/public_document_details.aspx?lang=en-US&id=28 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: twcert
Published: 2018-11-23T00:00:00
Updated: 2019-02-11T19:57:01
Reserved: 2018-09-26T00:00:00
Link: CVE-2018-17542
JSON object: View
NVD Information
Status : Modified
Published: 2019-02-11T20:29:00.443
Modified: 2019-10-09T23:36:42.503
Link: CVE-2018-17542
JSON object: View
Redhat Information
No data.
CWE