CVE-2024-6048: Openfind Mailaudit
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploit this vulnerability to inject system commands and execute them on the remote server.
Affected products
- Openfind Mailaudit: before 5.2.10.094 (fixed in 5.2.10.094); before 6.1.7.037 (fixed in 6.1.7.037)
- Openfind Mailaudit 5.0
- Openfind Mailaudit 6.0
- Openfind Mailgates: before 5.2.10.094 (fixed in 5.2.10.094); before 6.1.7.037 (fixed in 6.1.7.037)
- Openfind Mailgates 5.0
- Openfind Mailgates 6.0
Published 2024-06-17. Last modified 2026-06-17.