Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-32371 PoC — HSC Cybersecurity HC Mailinspector 安全漏洞

Source
Associated Vulnerability
Title:HSC Cybersecurity HC Mailinspector 安全漏洞 (CVE-2024-32371)
Description:An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0.
Readme
# CVE-2024-32371 Description

## Description
A vulnerability identified as CVE-2024-32371 allows an attacker to elevate privileges by changing the `type` parameter from 1 to 0. This vulnerability enables an attacker with a regular user account to escalate their privileges and gain administrative access to the system.

Versions: Discovered in HSC Mailinspector 5.2.17-3 but applicable to all versions up to 5.2.18.

## Vulnerable Parameter
- **Parameter:** `type`
- **Affected Values:** Changing the value from 1 (normal user) to 0 (administrator)

## Vulnerability Explanation
The vulnerability arises due to insufficient access control checks on the `type` parameter. By manipulating the value of the `type` parameter in the request payload, an attacker can modify their user account's permissions from a regular user to an administrator.

## Attack Scenario
To exploit this vulnerability, an attacker can intercept or craft a request with the `type` parameter set to 0, indicating administrator privileges. By submitting this malicious request, the attacker can bypass the intended access control mechanisms and gain unauthorized access as an administrator.

## Impact
Successful exploitation of CVE-2024-32371 allows an attacker to perform administrative actions within the system, such as:
- Accessing sensitive data or functionalities restricted to administrators.
- Modifying system configurations or user privileges.
- Performing malicious activities with elevated privileges, potentially leading to further compromise or data breaches.


![alt text](image.png)

![alt text](image-1.png)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →