nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-48974 CVE-2023-48974
CRITICAL
Axigen < 10.5.7 - Persistent Cross-Site Scripting
Record summary
CVE-2023-48974 has a selected CVSS score of 9.6 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBAxigen < 10.5.7 - Persistent Cross-Site ScriptingExploitDB exploitby Vincent McRae_ Mesut CetinNot analyzed1 file
Repository PoCs
GitHubvinnie1717/CVE-2023-48974Repository PoCby vinnie1717Stars: 0Not analyzed1 file
References
3axigen.com
https://www.axigen.com/mail-server/download axigen.com
https://www.axigen.com/updates/axigen-10.3.3.61