Description
HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, or path restriction. This allows a remote attacker to exploit Path Traversal techniques to read arbitrary files from the underlying operating system and application directories, leading to sensitive information disclosure.
Published: 2026-05-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 19 May 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 May 2026 19:30:00 +0000

Type Values Removed Values Added
Title Path Traversal LFI Enables Remote File Disclosure in HSC MailInspector

Tue, 19 May 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:hsclabs:mailinspector:5.3.3-7:*:*:*:*:*:*:*

Tue, 19 May 2026 17:15:00 +0000

Type Values Removed Values Added
Title Local File Inclusion in HSC MailInspector v5.3.3-7
Weaknesses CWE-22

Tue, 19 May 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 18 May 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local File Inclusion in HSC MailInspector v5.3.3-7
First Time appeared Hsclabs
Hsclabs mailinspector
Weaknesses CWE-22
Vendors & Products Hsclabs
Hsclabs mailinspector

Mon, 18 May 2026 17:45:00 +0000

Type Values Removed Values Added
Description HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, or path restriction. This allows a remote attacker to exploit Path Traversal techniques to read arbitrary files from the underlying operating system and application directories, leading to sensitive information disclosure.
References

Subscriptions

Hsclabs Mailinspector
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-19T13:42:21.450Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-29962

cve-icon Vulnrichment

Updated: 2026-05-19T13:02:35.944Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-18T18:17:21.383

Modified: 2026-06-17T10:29:57.493

Link: CVE-2026-29962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-19T19:15:12Z

Weaknesses