ASUS Download Master Vulnerable to Reflected Cross-site Scripting Attacks
CVE-2024-31159
4.8MEDIUM
What is CVE-2024-31159?
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.
Affected Version(s)
Download Master earlier <= 3.1.0.113