VYPR

Winnmp

by Winnmp

CVEs (2)

  • CVE-2024-5406MedMay 27, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via index page in from, subject, text and hash parameters. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their session details.

  • CVE-2024-5405MedMay 27, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via /tools/redis.php page in the k, hash, key and p parameters. This vulnerability could allow a remote user to submit a specially crafted JavaScript payload for an authenticated user to retrieve…