Medium severity6.1NVD Advisory· Published Jun 28, 2024· Updated Jun 17, 2026
CVE-2024-3801
CVE-2024-3801
Description
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET header parameters. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:conceptintermedia:s\@m_cms:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:conceptintermedia:s\@m_cms:*:*:*:*:*:*:*:*range: <=3.3
- (no CPE)
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
2- cert.pl/en/posts/2024/06/CVE-2024-3800nvdThird Party Advisory
- cert.pl/posts/2024/06/CVE-2024-3800nvdThird Party Advisory
News mentions
0No linked articles in our index yet.