1 results (0.003 seconds)
CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0
CVE-2024-0246 – IceWarp Utility Download cross site scripting
https://notcve.org/view.php?id=CVE-2024-0246
A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of the file /install/ of the component Utility Download Handler. The manipulation of the argument lang with the input 1%27"()%26%25<zzz><ScRiPt>alert(document.domain)</ScRiPt> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?ctiid.249759 https://vuldb.com/?id.249759 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •