CVE-2024-47801

Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.
Configurations

No configuration.

History

25 Oct 2024, 12:56

Type Values Removed Values Added
Summary
  • (es) Los equipos multifunción Sharp y Toshiba Tec procesan incorrectamente los parámetros de consulta en las solicitudes HTTP, lo que genera una vulnerabilidad de cross-site scripting reflejado. Acceder a una URL manipulada que apunta a un producto afectado puede provocar la ejecución de una secuencia de comandos maliciosa en el navegador web.

25 Oct 2024, 09:15

Type Values Removed Values Added
References
  • {'url': 'https://global.sharp/products/copier/info/info_security_2024-10-25.html', 'source': 'vultures@jpcert.or.jp'}
  • () https://global.sharp/products/copier/info/info_security_2024-10.html -

25 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-25 07:15

Updated : 2024-10-25 12:56


NVD link : CVE-2024-47801

Mitre link : CVE-2024-47801

CVE.ORG link : CVE-2024-47801


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')