CVE-2024-6741
15.07.2024, 09:15
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openfind | mail2000 | 7.0 |
| openfind | mail2000 | 8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References