Back to Database
Status published
Medium
CVE-2024-6740
Openfind Mail2000 - Stored XSS
Vulnerability Description
Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-6740
Credits & Attribution
No credits recorded in the NVD database.
References
More from Openfind
View All →CVE-2024-6741
Openfind Mail2000 - HttpOnly flag bypass
Medium
5.8
CVE-2024-6739
Openfind MailGates and MailAudit - Sensitive Cookie Without 'HttpOnly' Flag
Medium
5.3
CVE-2024-6048
Openfind MailGates and MailAudit - OS Command Injection
Critical
9.8
CVE-2024-5400
Openfind Mail2000 - OS Command Injection
High
8.8
CVE-2024-5399
Openfind Mail2000 - OS Command Injection
High
7.2
Affected Vendor
Openfind
View all reports →Affected Software
Mail2000 V7.0, Mail2000 V8.0
Vulnerable Versions:
all
Timeline
Official Publish:
July 15th, 2024
Last Modified:
August 1st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N