Vulnerabilities > Openfind

DATE CVE VULNERABILITY TITLE RISK
2019-11-20 CVE-2019-15071 Cross-site Scripting vulnerability in Openfind Mail2000 6.0/7.0
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication.
network
low complexity
openfind CWE-79
6.1
2019-06-19 CVE-2019-9763 Cross-site Scripting vulnerability in Openfind Mail2000 6.0
An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail.
network
low complexity
openfind CWE-79
6.1