CVE-2024-50601

Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further exploitation via a multi-stage attack. Fixed in versions 10.3.3.67, 10.4.42, and 10.5.29.
Configurations

No configuration.

History

12 Nov 2024, 16:35

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

12 Nov 2024, 13:55

Type Values Removed Values Added
Summary
  • (es) Las vulnerabilidades XSS persistentes y reflejado en la cookie themeMode y el parámetro URL _h de Axigen Mail Server hasta la versión 10.5.28 permiten a los atacantes ejecutar código JavaScript arbitrario. Su explotación podría provocar el secuestro de sesiones, la fuga de datos y una mayor explotación mediante un ataque de varias etapas. Se corrigió en las versiones 10.3.3.67, 10.4.42 y 10.5.29.

11 Nov 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-11 23:15

Updated : 2024-11-12 16:35


NVD link : CVE-2024-50601

Mitre link : CVE-2024-50601

CVE.ORG link : CVE-2024-50601


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')