herolab.usd.de
https://herolab.usd.de/security-advisories CVE-2023-38194
MEDIUMNuclei
SuperWebMailer - Cross-Site Scripting
Record summary
CVE-2023-38194 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryMEDIUMSuperWebMailer - Cross-Site ScriptingCVSS 6.1
An issue was discovered in SuperWebMailer 9.00.0.01710 that allows keepalive.php XSS via a GET parameter.
Impact
Successful exploitation could allow an attacker to execute malicious scripts in the context of a user's browser, leading to potential data theft or account compromise.
Remediation
Implement input validation and output encoding to prevent XSS attacks in the SuperWebMailer keepalive.php script.
WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023superwebmailerxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:superwebmailer:superwebmailer:9.00.0.01710:*:*:*:*:*:*:*
Shodan: title:"SuperWebMailer"
https://herolab.usd.de/security-advisories/usd-2023-0013/ https://nvd.nist.gov/vuln/detail/CVE-2023-38194
Source: ProjectDiscovery
References
3herolab.usd.de
https://herolab.usd.de/security-advisories/usd-2023-0013 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-38194