Description AcuToWeb v.10.5.0.7577C8b 版本存在 XSS 漏洞,该漏洞源于容易受到反射型跨站脚本攻击,允许远程攻击者通过 index.php组件执行任意 js 代码。
References https://nvd.nist.gov/vuln/detail/CVE-2024-42852 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-42852.yaml https://access.redhat.com/security/cve/cve-2024-42852 https://cve.imfht.com/detail/CVE-2024-42852?lang=en https://www.cve.org/CVERecord?id=CVE-2024-42852 https://s4e.io/tools/acutoweb-server-cross-site-scripting-cve-2024-42852 https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2024-42852 https://cert.kenet.or.ke/cve-2024-42852-acutoweb-cross-site-scripting-xss https://cxsecurity.com/cveshow/CVE-2024-42852/ https://ddpoc.com/DVB-2025-9679.html
Related VulnerabilitiesPoCCVE-2024-42852: AcuToWeb server/10.5.0.7577c8b - Cross-Site Scripting(CVE-2023-42852) iOS 内核 逻辑漏洞