An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NHsclabs Mailinspector
APPHsclabs5.2.17-3 – 5.2.19 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2024-32370CRITICAL9.8PL ✓same product
HSC Mailinspector — nieautoryzowany dostęp do danych przez parametr id
CVE-2026-29963HIGH7.5same product
HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input...
CVE-2026-29962HIGH7.5same product
HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of u...
CVE-2024-34470HIGH8.6same product
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vuln...
CVE-2026-29965MEDIUM6.1same product
HSC MailInspector 5.3.3-7 jest podatny na XSS w endpoincie /police/WarningUrlPage.php ze względu na niedostate...