Description
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.
No analysis available yet.
Remediation
Vendor Solution
Update Mail2000 V7.0 to Patch 131 or later Update Mail2000 V8.0 to Patch 044 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47778 | Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled. |
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:41:04.558Z
Reserved: 2024-07-15T03:34:25.851Z
Link: CVE-2024-6741
Updated: 2024-08-01T21:41:04.558Z
Status : Modified
Published: 2024-07-15T09:15:03.117
Modified: 2024-11-21T09:50:13.487
Link: CVE-2024-6741
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD