Description
PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_script/index.php page in all visible parameters. An attacker could create a specially crafted URL, send it to a victim and retrieve their session details.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1779 | PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_script/index.php page in all visible parameters. An attacker could create a specially crafted URL, send it to a victim and retrieve their session details. |
Github GHSA |
GHSA-rq7f-j68f-mqh3 | PHP Server Monitor vulnerable to Cross-site Scripting |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T21:11:12.469Z
Reserved: 2024-05-24T07:22:57.202Z
Link: CVE-2024-5312
Updated: 2024-08-01T21:11:12.469Z
Status : Deferred
Published: 2024-05-24T11:15:10.017
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-5312
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA