Record summary

CVE-2023-40355 has a selected CVSS score of 5.4 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2024 · Source: CVE List

Proofs of concept

1

Repository PoCs

GitHubace-83/CVE-2023-40355Repository PoCby ace-83Stars: 0Not analyzed2 files

2.3 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMAxigen WebMail - Cross-Site ScriptingCVSS 5.4

Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.

Impact

Authenticated attackers can inject malicious JavaScript through various parameters in the version switching logic, potentially stealing email credentials and accessing sensitive communications of Axigen webmail users.

Remediation

Update Axigen to version 10.3.3.59, 10.4.19, or 10.5.5 or later that properly sanitizes input parameters in the version switching logic.

WeaknessesCWE-79
Authorsamir-h-fallahi
Template tagscvecve2023xssaxigenwebmailvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:axigen:axigen_mobile_webmail:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-1247684400
FOFA: icon_hash=-1247684400

Source: ProjectDiscovery

References

2