CVE-2020-25849: Openfind MailGates/MailAudit - Command Injection
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-25849?
CVE-2020-25849 is a Command Injection vulnerability in MailGates and MailAudit products.
What is the severity of CVE-2020-25849?
CVE-2020-25849 has a severity level of critical (8.8).
Which software products are affected by CVE-2020-25849?
The affected software products are Openfind MailAudit version 4.0 and 5.0, as well as Openfind MailGates version 4.0 and 5.0.
How can CVE-2020-25849 be exploited?
CVE-2020-25849 can be exploited by injecting and executing system commands from the cgi parameter after obtaining the user's access token.
Where can I find more information about CVE-2020-25849?
More information about CVE-2020-25849 can be found at the following URL: [https://www.twcert.org.tw/tw/cp-132-4118-6292c-1.html](https://www.twcert.org.tw/tw/cp-132-4118-6292c-1.html)