Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the NetWin team in version 78e.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34041 | A Cross-Site Scripting (XSS) vulnerability in SurgeMail v78c2 could allow an attacker to execute arbitrary JavaScript code via an elaborate payload injected into vulnerable parameters. |
Fri, 29 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 Nov 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Scripting (XSS) vulnerability in SurgeMail v78c2 could allow an attacker to execute arbitrary JavaScript code via an elaborate payload injected into vulnerable parameters. | |
| Title | Cross-Site Scripting (XSS) en SurgeMail de NetWin | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-11-29T13:25:05.049Z
Reserved: 2024-11-29T08:20:32.936Z
Link: CVE-2024-11990
Updated: 2024-11-29T13:25:00.705Z
Status : Deferred
Published: 2024-11-29T13:15:04.170
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-11990
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:30Z
EUVD