Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026041709043838 | Publication Time | 2026/04/17 09:16 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/04/17 09:16 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Hong Ji Technology | iSherlock - OS Command Injection |
|||
| [Content] Forwarded from TWCERTCC-200-202604-00000015 【Hong Ji Technology | iSherlock - OS Command Injection】(CVE-2026-6349, CVSS: 9.8) iSherlock, developed by Hong Ji Technology, contains an OS Command Injection vulnerability. An unauthenticated local attacker may inject arbitrary operating system commands and execute them on the server. (Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform] Hgiga iSherlock versions 4.5 and 5.5 (including MailSherlock, SpamSherlock, and AuditSherlock) iSherlock-base-4.5 versions earlier than 476 iSherlock-audit-4.5 versions earlier than 261 iSherlock-base-5.5 versions earlier than 476 iSherlock-audit-5.5 versions earlier than 261 |
|||
| [Recommended Actions] Please update iSherlock-base-4.5 to version 476 or later, update iSherlock-audit-4.5 to version 261 or later, update iSherlock-base-5.5 to version 476 or later, and update iSherlock-audit-5.5 to version 261 or later. |
|||
| [Reference] 1. https://www.twcert.org.tw/tw/cp-132-10842-3f255-1.html |
|||