VYPR
Unrated severityNVD Advisory· Published Jul 15, 2024· Updated Aug 1, 2024

Openfind Mail2000 - Stored XSS

CVE-2024-6740

Description

Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks.

Affected products

3
  • Openfind/Mail2000llm-fuzzy3 versions
    (expand)+ 2 more
    • (no CPE)
    • (no CPE)range: all
    • (no CPE)range: all

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.