CVE-2024-6739

CVSS V2 None CVSS V3 None
Description
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
Overview
  • CVE ID
  • CVE-2024-6739
  • Assigner
  • twcert
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-15T03:15:03.815Z
  • Last Modified Date
  • 2024-07-15T03:17:02.773Z
History
Created Old Value New Value Data Type Notes
2024-07-15 13:03:39 Added to TrackCVE