Arbitrary Script Execution Vulnerability in Energy Management Controller
CVE-2024-23786
9.3CRITICAL
What is CVE-2024-23786?
A cross-site scripting vulnerability exists in the Sharp Energy Management Controller with Cloud Services models JH-RVB1 and JH-RV11 for versions Ver.B0.1.9.1 and earlier. This vulnerability allows an attacker with network access to execute arbitrary scripts in the web browsers of users accessing the management interface of the affected products. Exploitation of this flaw may lead to unauthorized actions being performed on behalf of the affected users, potentially compromising sensitive information and overall system integrity.
Affected Version(s)
Energy Management Controller with Cloud Services JH-RVB1 Ver.B0.1.9.1 and earlier
Energy Management Controller with Cloud Services JH-RV11 Ver.B0.1.9.1 and earlier