First published: Sun Nov 01 2020(Updated: )
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Openfind Mailaudit | =4.0 | |
Openfind Mailaudit | =5.0 | |
Openfind MailGates | =4.0 | |
Openfind MailGates | =5.0 |
Update Patch to 5.2.8.048 version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25849 is a Command Injection vulnerability in MailGates and MailAudit products.
CVE-2020-25849 has a severity level of critical (8.8).
The affected software products are Openfind MailAudit version 4.0 and 5.0, as well as Openfind MailGates version 4.0 and 5.0.
CVE-2020-25849 can be exploited by injecting and executing system commands from the cgi parameter after obtaining the user's access token.
More information about CVE-2020-25849 can be found at the following URL: [https://www.twcert.org.tw/tw/cp-132-4118-6292c-1.html](https://www.twcert.org.tw/tw/cp-132-4118-6292c-1.html)