CVE-2024-6739

MEDIUM

MailGates/MailAudit - XSS

Title source: llm
STIX 2.1

Description

The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-7927-03837-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-7928-04e8a-2.html

Scores

CVSS v3 5.3
EPSS 0.0012
EPSS Percentile 30.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732 CWE-1004
Status published
Products (2)
openfind/mailaudit < 6.1.7.040
openfind/mailgates < 6.1.7.040
Published Jul 15, 2024
Tracked Since Feb 18, 2026