Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pvxg-5348-rxvf

Опубликовано: 15 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

EPSS

Процентиль: 31%
0.00119
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1004
CWE-732
CWE-79

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

EPSS

Процентиль: 31%
0.00119
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1004
CWE-732
CWE-79