go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Openfind Mail2000 - Broken Access Control

TVN ID TVN-202008001
CVE ID CVE-2020-12776
CVSS 6.6 (Medium)
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
Affected Products Mail2000 7.0
Description Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the administrator access token or cookie.
Solution Update Patch to 091 of SP4, or contact with Openfind.
Credit Openfind technical department
Public Date 2020-08-31
Top