CVE-2024-11990: Cross-Site Scripting (XSS) en SurgeMail de NetWin
A Cross-Site Scripting (XSS) vulnerability in SurgeMail v78c2 could allow an attacker to execute arbitrary JavaScript code via an elaborate payload injected into vulnerable parameters.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11990?
CVE-2024-11990 is classified as a medium severity vulnerability due to potential exploitation via Cross-Site Scripting.
How do I fix CVE-2024-11990?
To fix CVE-2024-11990, ensure that you are using the latest version of SurgeMail where the vulnerability has been addressed.
What are the potential impacts of CVE-2024-11990?
The potential impacts of CVE-2024-11990 include execution of arbitrary JavaScript code, which could lead to unauthorized actions on behalf of the user.
Who is affected by CVE-2024-11990?
CVE-2024-11990 affects users of NetWin SurgeMail version 78c2 and potentially earlier versions.
How can an attacker exploit CVE-2024-11990?
An attacker can exploit CVE-2024-11990 by injecting crafted JavaScript into the vulnerable parameters, allowing for malicious actions.