The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mailaudit | Openfind | * | 6.1.7.040 (excluding) |
Mailgates | Openfind | * | 6.1.7.040 (excluding) |