CVE-2024-5406: Wtriple Winnmp

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via index page in from, subject, text and hash parameters. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their session details.

Affected products

Published 2024-05-27. Last modified 2026-06-17.