The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Mailaudit | Openfind | * | 6.1.7.040 (excluding) | 
| Mailgates | Openfind | * | 6.1.7.040 (excluding) |