CVE-2024-9007
LOW NUCLEI123solar 1.8.4.5 - Cross-Site Scripting via date1 Parameter in detailed.php
Title source: llmExploitation Summary
CVE-2024-9007 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named 94bf9ab7ad0ccb7fbdc02f172f37f0e2ea08d48f. It is recommended to apply a patch to fix this issue.
Nuclei Templates (1)
123Solar 1.8.4.5 - Cross-Site Scripting
MEDIUMVERIFIEDby ritikchaddha
Shodan:
title:"123Solar"
FOFA:
title="123Solar"
References (6)
Core 6
Core References
Third Party Advisory vdb-entry
technical-description
https://vuldb.com/?id.278163
Permissions Required signature
permissions-required
https://vuldb.com/?ctiid.278163
Third Party Advisory third-party-advisory
https://vuldb.com/?submit.408299
Exploit, Third Party Advisory exploit
issue-tracking
https://github.com/jeanmarc77/123solar/issues/73
Exploit, Third Party Advisory issue-tracking
https://github.com/jeanmarc77/123solar/issues/73#issuecomment-2357648077
Scores
CVSS v3
3.5
EPSS
0.0093
EPSS Percentile
55.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
jeanmarc77/123solar
1.8.4.5
Published
Sep 19, 2024
Tracked Since
Feb 18, 2026