Record summary

CVE-2024-2391 has a selected CVSS score of 2.4 (low); EIP currently links 1 catalogued exploit.

Description

A vulnerability was found in EVE-NG 5.0.1-13 and classified as problematic. Affected by this issue is some unknown functionality of the component Lab Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-256442 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

EVE-NG

CVE List5.0.1-13affected

Proofs of concept

1

Catalogued exploits

ExploitDBEve-ng 5.0.1-13 - Stored Cross-Site Scripting (XSS)ExploitDB exploitby @casp3r0x0 hassan ali al-khafajiNot analyzed1 file
ExploitDB

PoC details

References

4