by @alchemist
21 Jun 2024

Mailcow with XSS and Path traversal (CVE-2024-31204 and CVE-2024-30270)

by @alchemist
21 Jun 2024

Mailcow with XSS and Path traversal (CVE-2024-31204 and CVE-2024-30270)

CVEs

6.2 Medium Severity

PoC video

Summary

Mailcow's XSS and file overwrite vulnerabilities allow attackers to inject code, hijack sessions, and execute commands, highlighting critical security risks.

Description

users/photos/clm4pm8ebnpz71gn2efjy7ime.jpg

@alchemist

70 posts

working on it.

Total vcoins

29.1K

Social media links

Comments (0)