CVE-2020-7810
hslogin2.dll ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. This is due to a lack of integrity verification of the policy files referenced in the update process, and a remote attacker could induce a user to crafted web page, causing damage such as malicious code infection.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.20%
- CWE
- CWE-353
- Published
- 2020-08-07
- Last modified
- 2026-03-14
Affected products
- Handysoft, Inc. hslogin2.dll
Weakness type
Related vulnerabilities
- CVE-2021-26608 — handysoft groupware arbitrary file download and execution vulnerability
- CVE-2020-10266 — RVD#1487: No integrity checks on UR+ platform artifacts when installed in the robot
- CVE-2020-7808 — RAONWIZ Inc K Upload, arguments modiffication via missing support for integrity check vulnerability
- CVE-2019-11480 — Ubuntu kernel snap build process could use unauthenticated sources
- CVE-2021-28545 — Acrobat Reader DC Missing Support for Integrity Check
- CVE-2019-12804 — Hunesion i-oneNet Missing Support for Integrity Check vulnerability
- CVE-2023-32475 — Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system c
- CVE-2025-48500 — BIG-IP APM VPN web client for macOS vulnerability