PT-2020-13264 · Openfind · Openfind Mailgates

Published

2020-06-23

·

Updated

2021-07-21

·

CVE-2020-12782

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Openfind MailGates (affected versions not specified)
Description The issue is related to a Command Injection flaw. When Openfind MailGates receives an email with specific strings, malicious code in the mail attachment can be triggered, allowing unauthorized access to system files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12782

Affected Products

Openfind Mailgates