CVE-2024-42678

MEDIUM

Super easy enterprise management system <1.0.0 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-42678. PoCs published by WarmBrew.

AI-analyzed exploit summary The repository contains detailed technical writeups for multiple CVEs, including CVE-2024-42678, with descriptions, affected versions, and proof-of-concept code snippets. It provides insights into vulnerabilities like XSS, SQL injection, and insecure permissions in various software products.

Description

Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the /WebSet/DlgGridSet.html component.

Exploits (1)

github WRITEUP 3 stars
by WarmBrew · poc
https://github.com/WarmBrew/web_vul/tree/main/CVES/CVE-2024-42678.md

The repository contains detailed technical writeups for multiple CVEs, including CVE-2024-42678, with descriptions, affected versions, and proof-of-concept code snippets. It provides insights into vulnerabilities like XSS, SQL injection, and insecure permissions in various software products.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Moderate
Reliability
Theoretical
Target: Super easy enterprise management system <=1.0.0
No auth needed
Prerequisites: Access to the vulnerable component /WebSet/DlgGridSet.html
devstral-2 · analyzed Feb 27, 2026 Full analysis →

Scores

CVSS v3 6.1
EPSS 0.0033
EPSS Percentile 24.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
cysoft168/super_easy_enterprise_management_system < 1.0.0
Published Aug 15, 2024
Tracked Since Feb 18, 2026