Mail2000 Vulnerability Allows Arbitrary System Command Execution
CVE-2024-5400
8.8HIGH
What is CVE-2024-5400?
A vulnerability exists in Openfind Mail2000 where improper filtering of parameters in certain CGI scripts allows an attacker with standard access to execute arbitrary system commands on the affected server. This flaw poses significant risks as it can lead to unauthorized control over the server environment, enabling potential data breaches and further system compromise.
Affected Version(s)
Mail2000 V8.0 earlier
News Articles

CVE-2024-5400 : OPENFIND MAIL2000 8.0 CGI OS COMMAND INJECTION - Cloud WAF
CVE-2024-5400 : Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.