CVE-2024-6740: Openfind Mail2000 - Stored XSS
Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Openfind Mail2000to a version that resolves this vulnerability.Fixed in 7.0Patch Patch 131 - Upgrade
Upgrade
Openfind Mail2000to a version that resolves this vulnerability.Fixed in 8.0Patch Patch 044
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6740?
CVE-2024-6740 has a high severity rating due to its potential for allowing unauthenticated remote attackers to perform Stored Cross-site scripting attacks.
How do I fix CVE-2024-6740?
To mitigate CVE-2024-6740, ensure that email attachments are properly validated and consider applying any available patches from Openfind.
What versions of Openfind Mail2000 are affected by CVE-2024-6740?
CVE-2024-6740 affects Openfind Mail2000 versions 7.0 and 8.0.
What type of attack can be executed through CVE-2024-6740?
CVE-2024-6740 allows for Stored Cross-site scripting attacks via maliciously crafted email attachments.
Is authentication required to exploit CVE-2024-6740?
No, CVE-2024-6740 can be exploited by unauthenticated remote attackers.