Record summary

CVE-2023-48974 has a selected CVSS score of 9.6 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 8, 2024 · Source: CVE List

Proofs of concept

2

Catalogued exploits

ExploitDBAxigen < 10.5.7 - Persistent Cross-Site ScriptingExploitDB exploitby Vincent McRae_ Mesut CetinNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubvinnie1717/CVE-2023-48974Repository PoCby vinnie1717Stars: 0Not analyzed1 file

191 B

GitHub

PoC details

References

3