CVE Database
/

CVE-2024-6741

Back to search

CVE-2024-6741

Published: Jul 15, 2024

Modified: Aug 1, 2024

PUBLISHED

CVSS v3.1

5.8

MEDIUM

Description

Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.

VendorProductVersions

Openfind

Mail2000 V7.0

affected
all - < Patch 131

Openfind

Mail2000 V8.0

affected
all - < Patch 044

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

Low

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now