CVE-2024-9007

LOW NUCLEI

123solar 1.8.4.5 - Cross-Site Scripting via date1 Parameter in detailed.php

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-9007 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named 94bf9ab7ad0ccb7fbdc02f172f37f0e2ea08d48f. It is recommended to apply a patch to fix this issue.

Nuclei Templates (1)

123Solar 1.8.4.5 - Cross-Site Scripting
MEDIUMVERIFIEDby ritikchaddha
Shodan: title:"123Solar"
FOFA: title="123Solar"

References (6)

Core 6
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.278163
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.278163
Third Party Advisory third-party-advisory
https://vuldb.com/?submit.408299
Exploit, Third Party Advisory exploit issue-tracking
https://github.com/jeanmarc77/123solar/issues/73

Scores

CVSS v3 3.5
EPSS 0.0093
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
jeanmarc77/123solar 1.8.4.5
Published Sep 19, 2024
Tracked Since Feb 18, 2026