Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-32370 — An issue in HSC Cybersecurity HSC Mailinspector version 5.2.17-3 has been identified, allowing a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component. | Kitploit
Tools/GitHubGitHub/chucrutis/cve-2024-32370
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubchucrutis/cve-2024-32370

CVE-2024-32370

An issue in HSC Cybersecurity HSC Mailinspector version 5.2.17-3 has been identified, allowing a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.

View Repository
122 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-32370

Vulnerability Description

Issue

An issue in HSC Cybersecurity HSC Mailinspector version 5.2.17-3 has been identified, allowing a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.

Vulnerable Component

  • Component: mliSystemUsers.php
  • Version: 5.2.17-3 up to 5.2.18

Vulnerable Parameter

  • Parameter: id
  • Payload: flagChangeUserAccount=true&exe=load&id=501762441

Vulnerability Explanation

The vulnerability arises due to insufficient input validation and sanitization of the id parameter in the mliSystemUsers.php component. Attackers can exploit this flaw by sending a specially crafted payload to the id parameter, enabling them to obtain sensitive information from the system.

Attack Scenario

A remote attacker can exploit this vulnerability by manipulating the id parameter in the payload. By sending a crafted request with a malicious id value, the attacker can trick the application into disclosing sensitive information, such as user account details or system configuration data.

Impact

If successfully exploited, the vulnerability could lead to the unauthorized disclosure of sensitive information stored within the HSC Mailinspector system. This information disclosure may include user credentials, email content, or other confidential data, posing a significant risk to the confidentiality and integrity of the system.

alt text

Download Tool