Record summary

CVE-2024-24131 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMSuperWebMailer 9.31.0.01799 - Cross-Site ScriptingCVSS 6.1

SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.

Impact

Unauthenticated attackers can execute arbitrary JavaScript in a victim's browser via the api.php component, potentially stealing cookies or session tokens.

Remediation

Update SuperWebMailer to a version newer than 9.31.0.01799.

WeaknessesCWE-79
AuthorsDhiyaneshDK
Template tagscvecve2024superwebmailerxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:superwebmailer:superwebmailer:9.31.0.01799:*:*:*:*:*:*:*
Shodan: title:"SuperWebMailer"
Shodan: http.title:"superwebmailer"
FOFA: title="superwebmailer"
Google: intitle:"superwebmailer"

Source: ProjectDiscovery

References

2