ZeroHour

CVE-2020-25849

CVSS 3.1
8.8 high
EPSS
2%p82
Published
()
Modified
Description

MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.

Vendors
openfind
Products
mailaudit, mailgates
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.