github.com
https://github.com/Hebing123/cve/issues/14 CVE-2024-24131
MEDIUMNuclei
SuperWebMailer 9.31.0.01799 - Cross-Site Scripting
Record summary
CVE-2024-24131 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryMEDIUMSuperWebMailer 9.31.0.01799 - Cross-Site ScriptingCVSS 6.1
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.
Impact
Unauthenticated attackers can execute arbitrary JavaScript in a victim's browser via the api.php component, potentially stealing cookies or session tokens.
Remediation
Update SuperWebMailer to a version newer than 9.31.0.01799.
WeaknessesCWE-79
AuthorsDhiyaneshDK
Template tagscvecve2024superwebmailerxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:superwebmailer:superwebmailer:9.31.0.01799:*:*:*:*:*:*:*
Shodan: title:"SuperWebMailer"
Shodan: http.title:"superwebmailer"
FOFA: title="superwebmailer"
Google: intitle:"superwebmailer"
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-24131