CVE-2004-2548 describes multiple cross-site scripting (XSS) vulnerabilities in NetWin SurgeMail before version 2.0c and WebMail. Attackers can inject arbitrary web script or HTML through a crafted URI or the username field in the login form. This vulnerability has a CVSS score of 4.3, indicating medium attack complexity and potential for partial integrity impact, with no confidentiality or availability impact. While not listed on the KEV catalog, an exploit is available on ExploitDB, and it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0a2CPE matchmatch criteria | cpe:2.3:a:netwin:surgemail:*:*:*:*:*:*:*:* | ||
1.8aCPE matchmatch criteria | cpe:2.3:a:netwin:surgemail:1.8a:*:*:*:*:*:*:* | ||
1.8b3CPE matchmatch criteria | cpe:2.3:a:netwin:surgemail:1.8b3:*:*:*:*:*:*:* | ||
1.8dCPE matchmatch criteria | cpe:2.3:a:netwin:surgemail:1.8d:*:*:*:*:*:*:* | ||
1.8fCPE matchmatch criteria | cpe:2.3:a:netwin:surgemail:1.8f:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.