← volver
CVE-2024-8457

PLANET Technology switch devices - Stored cross-site scripting (XSS) in the User Management

CVSS 4.8 MEDIUMEPSS 0.3%CWE-79
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →