PT-2024-36018 · Winnmp · Winnmp
Rafael Pedrero
·
Published
2024-05-27
·
Updated
2024-05-28
·
CVE-2024-5405
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
WinNMP version 19.02
Description:
A vulnerability has been discovered that allows for an XSS attack via the /tools/redis.php page, specifically in the
k, hash, key, and p parameters. This could enable a remote user to submit a specially crafted JavaScript payload, allowing them to retrieve an authenticated user's session details.Recommendations:
For WinNMP version 19.02, consider disabling access to the /tools/redis.php page until a patch is available. Additionally, restrict the use of the
k, hash, key, and p parameters in this page to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winnmp