ZeroHour

CVE-2024-6739

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p38
Published
()
Modified
Description

The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

Vendors
openfind
Products
mailaudit, mailgates
Weakness
CWE-1004, CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.