CVE-2024-51122
Description
Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 alllows a remote attacker to execute arbitrary code via the ST, L, O, OU, CN parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
XSS vulnerability in Zertificon Z1 CertServer via certificate subject fields allows remote attackers to execute arbitrary scripts.
A cross-site scripting (XSS) vulnerability has been identified in Zertificon's Z1 SecureMail Z1 CertServer version 3.16.4-2516-debian12. The flaw resides in the handling of the certificate subject parameters ST, L, O, OU, and CN. Improper sanitization of user-supplied input allows an attacker to inject malicious scripts into the web interface.
To exploit this vulnerability, an attacker must be able to supply crafted values for any of the affected parameters when generating or modifying certificates. The attack can be conducted remotely without authentication, as the parameters are processed by the web server. Successful exploitation requires the victim to interact with the malicious link or content, such as clicking a crafted URL or viewing a manipulated certificate page.
If exploited, an attacker can execute arbitrary JavaScript in the context of the victim's browser session. This can lead to session hijacking, defacement, or theft of sensitive information displayed on the affected web pages. The CVSS v3 base score of 6.1 (Medium) reflects the need for user interaction but also the potential for significant impact on confidentiality and integrity.
As of the publication date (2025-02-12), no patch has been announced. Administrators are advised to restrict access to the certificate management interface and apply input validation as a workaround. The vulnerability is documented in public advisories [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: =3.16.4-2516-debian12
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.