Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2024-6741
Disclosure Date: July 15, 2024 (last updated July 20, 2024)
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.
0
Attacker Value
Unknown
CVE-2024-6740
Disclosure Date: July 15, 2024 (last updated July 17, 2024)
Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks.
0
Attacker Value
Unknown
CVE-2023-22902
Disclosure Date: February 24, 2023 (last updated February 24, 2025)
Openfind Mail2000 file uploading function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject JavaScript, conducting an XSS attack.
0
Attacker Value
Unknown
CVE-2020-12776
Disclosure Date: September 01, 2020 (last updated November 28, 2024)
Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the administrator access token or cookie.
0