RULE(RULE ID:338444)

Rule General Information
Release Date: 2024-09-29
Rule Name: SuperWebMailer 9.00.0.01710 Cross Site Scripting Vulnerability (CVE-2023-38192)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://herolab.usd.de/security-advisories/
https://herolab.usd.de/security-advisories/usd-2023-0011/
Solutions
Please contact the software vendor to update the software patch.