CVE-2024-6739

MEDIUM

Openfind MailGates and MailAudit < 6.1.7.040 - Session Cookie Theft via Missing HttpOnly Flag

Title source: llm
STIX 2.1

Description

The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-7927-03837-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-7928-04e8a-2.html

Scores

CVSS v3 5.3
EPSS 0.0045
EPSS Percentile 36.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1004 CWE-732
Status published
Products (2)
openfind/mailaudit < 6.1.7.040
openfind/mailgates < 6.1.7.040
Published Jul 15, 2024
Tracked Since Feb 18, 2026