5.8

CVE-2024-6741

Exploit

Openfind Mail2000 - HttpOnly flag bypass

Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenfindMail2000 Version7.0
OpenfindMail2000 Version8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.46
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
twcert@cert.org.tw 5.8 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

https://www.openfind.com.tw/taiwan/download/Openfind_OF-ISAC-24-007.pdf
Exploit
https://www.twcert.org.tw/en/cp-139-7941-b66e7-2.html
Third Party Advisory
https://www.twcert.org.tw/tw/cp-132-7940-0177a-1.html
Third Party Advisory