CVE-2024-2391

LOW

EVE-NG 5.0.1-13 - Cross-Site Scripting in Lab Handler

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-2391. PoCs published by @casp3r0x0 hassan ali al-khafaji.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in EVE-NG 5.0.1-13. The attacker creates a lab with a text label containing a malicious script, which executes when other users open the lab.

Description

A vulnerability was found in EVE-NG 5.0.1-13 and classified as problematic. Affected by this issue is some unknown functionality of the component Lab Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-256442 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Exploits (1)

exploitdb WORKING POC
by @casp3r0x0 hassan ali al-khafaji · textwebappsphp
https://www.exploit-db.com/exploits/51153

This exploit demonstrates a stored XSS vulnerability in EVE-NG 5.0.1-13. The attacker creates a lab with a text label containing a malicious script, which executes when other users open the lab.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: EVE-NG Free Community Edition Version 5.0.1-13
Auth required
Prerequisites: Access to create a lab in EVE-NG · Ability to insert a text label with malicious payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory vdb-entry
https://vuldb.com/?id.256442
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.256442
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/51153

Scores

CVSS v3 2.4
EPSS 0.0048
EPSS Percentile 37.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
eve-ng/eve-ng 5.0.1-13
Published Mar 12, 2024
Tracked Since Feb 18, 2026