CVE-2024-6739: Openfind Mailaudit
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
Affected products
- Openfind Mailaudit: before 6.1.7.040 (fixed in 6.1.7.040)
- Openfind Mailgates: before 6.1.7.040 (fixed in 6.1.7.040)
Published 2024-07-15. Last modified 2026-06-17.