Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47777 | Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks. |
Fixes
Solution
Update Mail2000 V7.0 to Patch 131 or later Update Mail2000 V8.0 to Patch 044 or later
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:41:04.575Z
Reserved: 2024-07-15T03:34:24.222Z
Link: CVE-2024-6740
Updated: 2024-08-01T21:41:04.575Z
Status : Modified
Published: 2024-07-15T08:15:03.087
Modified: 2024-11-21T09:50:13.357
Link: CVE-2024-6740
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD