CVE-2024-6048

Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploit this vulnerability to inject system commands and execute them on the remote server.
Configurations

No configuration.

History

21 Nov 2024, 09:48

Type Values Removed Values Added
References () https://www.twcert.org.tw/en/cp-139-7886-20b61-2.html - () https://www.twcert.org.tw/en/cp-139-7886-20b61-2.html -
References () https://www.twcert.org.tw/tw/cp-132-7885-a8013-1.html - () https://www.twcert.org.tw/tw/cp-132-7885-a8013-1.html -

17 Jun 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) MailGates y MailAudit de Openfind no filtran adecuadamente la entrada del usuario al analizar los archivos adjuntos de correo electrónico. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para inyectar comandos del sistema y ejecutarlos en el servidor remoto.

17 Jun 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-17 08:15

Updated : 2024-11-21 09:48


NVD link : CVE-2024-6048

Mitre link : CVE-2024-6048

CVE.ORG link : CVE-2024-6048


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')