Описание
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
Ссылки
- Exploit
- Third Party Advisory
- Third Party Advisory
- Exploit
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.1.7.040 (исключая)Версия до 6.1.7.040 (исключая)
Одно из
cpe:2.3:a:openfind:mailaudit:*:*:*:*:*:*:*:*
cpe:2.3:a:openfind:mailgates:*:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.00119
Низкий
5.3 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-1004
CWE-732
Связанные уязвимости
CVSS3: 5.3
github
больше 1 года назад
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
EPSS
Процентиль: 31%
0.00119
Низкий
5.3 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-1004
CWE-732