CVE-2024-50601

Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and further exploitation via a multi-stage attack. Fixed in versions 10.3.3.67, 10.4.42, and 10.5.29.
Configurations

No configuration.

History

No history.

Information

Published : 2024-11-11 23:15

Updated : 2024-11-12 16:35


NVD link : CVE-2024-50601

Mitre link : CVE-2024-50601

CVE.ORG link : CVE-2024-50601


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')