Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-07-15T08:26:32.252Z
Updated: 2024-08-01T21:41:04.558Z
Reserved: 2024-07-15T03:34:25.851Z
Link: CVE-2024-6741
Vulnrichment
Updated: 2024-08-01T21:41:04.558Z
NVD
Status : Modified
Published: 2024-07-15T09:15:03.117
Modified: 2024-11-21T09:50:13.487
Link: CVE-2024-6741
Redhat
No data.