CVE-2024-6739

5.3MEDIUM

The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

公開日: 7/15/2024更新日: 11/21/2024

説明

The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

AI分析AIによる分析

影響を受ける製品

openfindmailaudit
openfindmailgates

参照