Toshiba Printers Vulnerable to Cross-Site Scripting (XSS) Attacks
CVE-2024-27162

6.1MEDIUM

Key Information:

Vendor
Toshiba
Vendor
CVE Published:
14 June 2024

Summary

Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable to XSS and is loaded inside all the webpages provided by the printer. An attacker can steal the cookie of an admin user. As for the affected products/models/versions, see the reference URL.

Affected Version(s)

Toshiba Tec e-Studio multi-function peripheral (MFP) Linux see the reference URL

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

We expresses its gratitude to Pierre Barre for reporting relevant security vulnerabilities for our products.
.