CVE-2024-34058: Nethesis Nethserver
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
The WebTop package for NethServer 7 and 8 allows stored XSS (for example, via the Subject field if an e-mail message).
Affected products
- Nethesis Nethserver: version 7 only; version 8 only
Published 2024-05-17. Last modified 2026-06-17.