CVE-2024-6741

Publication date

2024-07-15 08:26:32

Family

twcert

State

PUBLISHED

Description

Openfinds Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.