CVE-2024-2391

LOW

Eve-ng - XSS

Title source: rule

Description

A vulnerability was found in EVE-NG 5.0.1-13 and classified as problematic. Affected by this issue is some unknown functionality of the component Lab Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-256442 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Exploits (1)

exploitdb WORKING POC
by @casp3r0x0 hassan ali al-khafaji · textwebappsphp
https://www.exploit-db.com/exploits/51153

Scores

CVSS v3 2.4
EPSS 0.0011
EPSS Percentile 29.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
eve-ng/eve-ng 5.0.1-13
Published Mar 12, 2024
Tracked Since Feb 18, 2026