Mail2000 Vulnerability Allows Arbitrary System Command Execution
CVE-2024-5400

8.8HIGH

Key Information:

Vendor
Openfind
Vendor
CVE Published:
27 May 2024

Badges

📰 News Worthy

Summary

A vulnerability exists in Openfind Mail2000 where improper filtering of parameters in certain CGI scripts allows an attacker with standard access to execute arbitrary system commands on the affected server. This flaw poses significant risks as it can lead to unauthorized control over the server environment, enabling potential data breaches and further system compromise.

Affected Version(s)

Mail2000 V8.0 earlier

News Articles

CVE-2024-5400 : OPENFIND MAIL2000 8.0 CGI OS COMMAND INJECTION - Cloud WAF

CVE-2024-5400 : Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by prophaze.com

  • Vulnerability published

  • Vulnerability Reserved

.