Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v3v6-h9vm-h39c

Опубликовано: 15 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.

Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.

EPSS

Процентиль: 39%
0.00175
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 5.8
nvd
больше 1 года назад

Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.

EPSS

Процентиль: 39%
0.00175
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-693