CVE-2024-9969

NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflected Cross-site Scripting (XSS) attack. The affected product is no longer maintained. It is recommended to upgrade to the new product.
Configurations

Configuration 1 (hide)

cpe:2.3:a:newtype:webeip:3.0:*:*:*:*:*:*:*

History

19 Oct 2024, 00:51

Type Values Removed Values Added
References () https://www.twcert.org.tw/en/cp-139-8135-ce1e6-2.html - () https://www.twcert.org.tw/en/cp-139-8135-ce1e6-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-8134-c476d-1.html - () https://www.twcert.org.tw/tw/cp-132-8134-c476d-1.html - Third Party Advisory
First Time Newtype webeip
Newtype
CPE cpe:2.3:a:newtype:webeip:3.0:*:*:*:*:*:*:*

15 Oct 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) NewType WebEIP v3.0 no valida correctamente la entrada del usuario, lo que permite que un atacante remoto con privilegios normales inserte JavaScript en parámetros específicos, lo que da como resultado un ataque de Cross Site Scripting (XSS) Reflejado. El producto afectado ya no recibe mantenimiento. Se recomienda actualizar al nuevo producto.

15 Oct 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-15 04:15

Updated : 2024-10-19 00:51


NVD link : CVE-2024-9969

Mitre link : CVE-2024-9969

CVE.ORG link : CVE-2024-9969


JSON object : View

Products Affected

newtype

  • webeip
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')