Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-50962 — A Cross-Site Scripting (XSS) vulnerability | Kitploit
Tools/GitHubGitHub/fdzdev/cve-2024-50962
Vulnerability AnalysisWeb Application ExploitationPhishingWeb SecurityLearning & Education
GitHubfdzdev/cve-2024-50962

CVE-2024-50962

A Cross-Site Scripting (XSS) vulnerability

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Cross-Site Scripting (XSS) in DonWeb Ferozo Webmail (CVE-2024-50962)

Description

A Cross-Site Scripting (XSS) vulnerability in Ferozo Webmail v1.1 allows attackers to execute arbitrary scripts via the Identities and Automatic Responses components. This vulnerability can be used to hijack user sessions, conduct phishing attacks, and steal credentials.

Attack Complexity

  • Low

Privileges Required

  • None

User Interaction

  • Required (Users need to interact with the component containing the injected script.)

Affected Components

  • Identities Page and Automatic Responses: Insufficient input validation allows malicious script injection.

Impact

  • Session Hijacking: Attackers can control user sessions.
  • Phishing: Embedded iframes can be used to conduct phishing attacks.

Remediation

  • Input Sanitization: Implement robust input validation and sanitization.
  • XSS Filtering: Apply a Content Security Policy (CSP) to prevent unauthorized script execution.

CVE-2024-50962
Reported by [Facundo Fernandez / Security Researcher]

Download Tool