First published: Mon Jul 15 2024(Updated: )
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Openfind Mailaudit | <6.1.7.040 | |
Openfind MailGates | <6.1.7.040 |
Update MailGates V6.0 to version 6.1.7.040 or later. Update MailAudit V6.0 to version 6.1.7.040 or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.