CVE-2024-51026
MEDIUMNetAdmin IAM 4.0.30319 - Cross-Site Scripting via BalloonSave.ashx Content Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-51026. PoCs published by BrotherOfJhonny.
AI-analyzed exploit summary This repository contains a detailed writeup describing a Cross-Site Scripting (XSS) vulnerability in NetAdmin IAM version 4.0.30319, specifically in the `/BalloonSave.ashx` endpoint via the `Content` parameter. It includes CVSS scoring, mitigation recommendations, and references to CWE entries.
Description
The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.
Exploits (1)
This repository contains a detailed writeup describing a Cross-Site Scripting (XSS) vulnerability in NetAdmin IAM version 4.0.30319, specifically in the `/BalloonSave.ashx` endpoint via the `Content` parameter. It includes CVSS scoring, mitigation recommendations, and references to CWE entries.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N