Openfind
Openfind Mail2000: vulnerabilidades y CVE
Openfind Mail2000 tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-6741 | Media (5.3) | 0.64% | — | 15 jul 2024 | Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the… |
| CVE-2024-6740 | Media (6.1) | 0.50% | — | 15 jul 2024 | Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks. |
| CVE-2024-5400 | Alta (8.8) | 0.58% | — | 27 may 2024 | Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server. |
| CVE-2024-5399 | Alta (7.2) | 0.56% | — | 27 may 2024 | Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the remote server. |
| CVE-2023-28705 | Media (6.1) | 0.43% | — | 2 jun 2023 | Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A remote attacker can exploit this vulnerability using phishing emails that contain malicious web pages… |
| CVE-2023-22902 | Media (5.4) | 0.43% | — | 27 mar 2023 | Openfind Mail2000 file uploading function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject JavaScript, conducting an XSS… |
| CVE-2020-12776 | Alta (7.2) | 0.83% | — | 1 sept 2020 | Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the administrator access token or cookie. |
| CVE-2019-15073 | Media (6.1) | 1.1% | — | 20 nov 2019 | An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments,… |
| CVE-2019-15072 | Media (6.1) | 1.5% | — | 20 nov 2019 | The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail… |
| CVE-2019-15071 | Media (6.1) | 1.6% | — | 20 nov 2019 | The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for… |
| CVE-2019-9763 | Media (6.1) | 1.2% | — | 19 jun 2019 | An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message (The vendor subsequently patched this). |