Web App Security Flaw Affects PLANET Switches
CVE-2024-8457

4.8MEDIUM

What is CVE-2024-8457?

Certain switch models from PLANET Technology are affected by a vulnerability in their web application due to improper validation of specific parameters. This flaw allows remote authenticated users with administrator privileges to inject and execute arbitrary JavaScript code, potentially leading to a Stored Cross-Site Scripting (XSS) attack. This vulnerability highlights the importance of stringent input validation in web applications to prevent unauthorized access and exploitation.

Affected Version(s)

GS-4210-24P2S hardware 3.0 0 < 3.305b240802

GS-4210-24PL4C hardware 2.0 0 < 2.305b240719

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-8457 : Web App Security Flaw Affects PLANET Switches