CVE-2024-24510: XSS
Published Sep 9, 2024
·Updated
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.
Affected Software
2 affected components
alinto SOGo<5.10.0
alinto SOGo<5.10.0
Remediation
Event History
Sep 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24510?
CVE-2024-24510 is classified as a high severity vulnerability due to its potential for remote code execution via cross-site scripting.
2
How do I fix CVE-2024-24510?
To fix CVE-2024-24510, upgrade Alinto SOGo to version 5.10.0 or later.
3
What type of vulnerability is CVE-2024-24510?
CVE-2024-24510 is a Cross Site Scripting (XSS) vulnerability.
4
What component of Alinto SOGo is affected by CVE-2024-24510?
The mail component of Alinto SOGo is affected by CVE-2024-24510.
5
Is CVE-2024-24510 exploitable by remote attackers?
Yes, CVE-2024-24510 can be exploited by remote attackers through the import function.