The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25850
Reference (s):
- https://www.twcert.org.tw/tw/cp-132-4258-0a8a0-1.html
- URL: https://www.twcert.org.tw/tw/cp-132-4258-0a8a0-1.html