Record summary

CVE-2023-38192 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 5, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMSuperWebMailer 9.00.0.01710 - Cross-Site ScriptingCVSS 6.1

An issue was discovered in SuperWebMailer 9.00.0.01710 allowing XSS via crafted incorrect passwords.

Impact

Successful exploitation could lead to unauthorized access or data theft.

Remediation

Implement input validation and output encoding to prevent XSS attacks.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023superwebmailerxssvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:superwebmailer:superwebmailer:9.00.0.01710:*:*:*:*:*:*:*
Shodan: title:"SuperWebMailer"

Source: ProjectDiscovery

References

3