CVE-2020-35741

Publication date

2020-12-31 07:45:50

Family

twcert

State

PUBLISHED

Description

HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.