Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploit this vulnerability to inject system commands and execute them on the remote server.
https://www.twcert.org.tw/tw/cp-132-7885-a8013-1.html
https://www.twcert.org.tw/en/cp-139-7886-20b61-2.html
Source: Mitre, NVD
Published: 2024-06-17
Updated: 2026-04-15
Base Score: 6.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P
Severity: Medium
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.00769