Vulnerabilities > Openfind
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-11-20 | CVE-2019-15071 | Cross-site Scripting vulnerability in Openfind Mail2000 6.0/7.0 The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. | 6.1 |
2019-06-19 | CVE-2019-9763 | Cross-site Scripting vulnerability in Openfind Mail2000 6.0 An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. | 6.1 |