
FortiMail zero-day (CVE-2024-11183) exploited in the wild — pre-auth RCE via SMTP. Attackers are hitting unpatched servers right now. Patches delayed for some versions. If you're running FortiMail, segment it yesterday. #infosec #zerodayexploit
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

FortiMail zero-day (CVE-2024-11183) exploited in the wild — pre-auth RCE via SMTP. Attackers are hitting unpatched servers right now. Patches delayed for some versions. If you're running FortiMail, segment it yesterday. #infosec #zerodayexploit
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | rumspeed | simple_side_tab | - | wordpress | - |