Toshiba Printers Vulnerable to Cross-Site Scripting (XSS) Attacks
CVE-2024-27162
6.1MEDIUM
Key Information:
- Vendor
- Toshiba
- Vendor
- CVE Published:
- 14 June 2024
Summary
Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable to XSS and is loaded inside all the webpages provided by the printer. An attacker can steal the cookie of an admin user. As for the affected products/models/versions, see the reference URL.
Affected Version(s)
Toshiba Tec e-Studio multi-function peripheral (MFP) Linux see the reference URL
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
We expresses its gratitude to Pierre Barre for reporting relevant security vulnerabilities for our products.