hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy files referenced in the update process, and a remote attacker could induce a user to crafted web page, causing damage such as malicious code infection.
2020-08-07T16:15:11.967
2024-11-21T05:37:50.830
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | handysoft | hslogin2.dll | ≤ 6.7.8.4 | Yes |
| Application | handysoft | hslogin2.dll | ≤ 7.3.4 | Yes |
| Operating System | microsoft | windows | - | No |