Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-51026_Overview — Sistema NetAdmin IAM 4 é vulnerável a Cross Site Scripting (XSS), no endpoint /BalloonSave.ashx | Kitploit
Tools/GitHubGitHub/brotherofjhonny/cve-2024-51026_overview
Vulnerability AnalysisWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubbrotherofjhonny/cve-2024-51026_overview

CVE-2024-51026_Overview

Sistema NetAdmin IAM 4 é vulnerável a Cross Site Scripting (XSS), no endpoint /BalloonSave.ashx

View Repository
21 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-51026 - Cross Site Scripting (XSS) Vulnerability in NetAdmin IAM

Description

The NetAdmin IAM system (version 4.0.30319) presents a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload in the Content= field. Any authenticated user can exploit this vulnerability by inserting a script in the "Content" field of a request within the described endpoint. This script will be executed whenever the vulnerable page is refreshed.

Vulnerability Details

  • Type: Cross Site Scripting (XSS)
  • Affected Version: 4.0.30319

CVSS Score and Attack Vectors

  • Base Score (CVSS): 7.3
  • Attack Vectors: CVSS Calculator
CVSS VectorDescription
AVN (Network)
ACL (Low)
PRL (Low)
UIR (Required)
SU (Unchanged)
CH (High)
IH (High)
AN (None)

Vulnerable Endpoint

  • URL: https://netadmin.mysystem/BalloonSave.ashx
  • Affected Parameter: Content=

Solution

Fix Status

  • Under Approval: The fix for this vulnerability is currently in the approval phase.

Mitigation Recommendations

Until the official fix is made available by the vendor, it is recommended to:

  1. Request a version update from the system vendor.
  2. Implement additional security measures, such as restrictions on user data input, to mitigate the risk of XSS injection.

Mitigation References

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
  • CWE-116: Improper Encoding or Escaping of Output
  • CWE-159: Improper Handling of Insufficient Privileges

For more details on this vulnerability or technical assistance in implementing mitigation measures, contact the vendor's security support.

Download Tool