Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-24086 — An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document. | Kitploit
Tools/GitHubGitHub/rxerium/cve-2022-24086
Vulnerability ScannersWeb Vulnerability ScannersVulnerability AnalysisWeb SecurityPenetration Testing
GitHubrxerium/cve-2022-24086

CVE-2022-24086

An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

View Repository
11311 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-24682 PoC

How does this detection method work?

As stated on the advisories versions 8.8.x before 8.8.15 patch 30 (update 1) are vulnerable to attacks, the template looks at the following versions:

          - "8.8"
          - "8.8.6"
          - "8.8.7"
          - "8.8.8"
          - "8.8.9"
          - "8.8.10"
          - "8.8.11"
          - "8.8.12"
          - "8.8.15"

How do I run this script?

  1. Download Nuclei from here
  2. Copy the template to your local system
  3. Run the following command: nuclei -u https://yourHost.com -t template.yaml

References

  • https://nvd.nist.gov/vuln/detail/CVE-2022-24682
  • https://blog.zimbra.com/2022/02/hotfix-available-5-feb-for-zero-day-exploit-vulnerability-in-zimbra-8-8-15/

Disclaimer

Use at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.

Contact

If you have any questions please do reach out to me via Signal or via email: [email protected].

If you'd like to support my work, feel free to donate via Buy Me a Coffee — your support means a lot and is truly appreciated!

Download Tool