« Volver al listado

CVE-2024-36494

Estado: AplazadaMedia (4.7)—

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at /cgi/slogin.cgi suffers from XSS due to improper input filtering of the -tsetup+-uuser parameter, which can only be exploited if the target user is not already logged in. This makes it ideal for login form phishing attempts.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-36494",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-36494",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-12T15:13:52.373592Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
      "affectedData": [
        {
          "vendor": "Image Access GmbH",
          "product": "Scan2Net",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "7.42B",
                  "status": "unaffected"
                }
              ],
              "version": "0",
              "lessThan": "7.42B",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-12-12T13:15:10.160",
  "references": [
    {
      "url": "https://r.sec-consult.com/imageaccess",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
    },
    {
      "url": "https://www.imageaccess.de/?page=SupportPortal&lang=en",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Dec/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at /cgi/slogin.cgi suffers from XSS due to improper input filtering of the -tsetup+-uuser parameter, which can only be exploited if the target user is not already logged in. This makes it ideal for login form phishing attempts."
    },
    {
      "lang": "es",
      "value": "Debido a la falta de desinfección de entrada, un atacante puede realizar ataques cross-site-scripting y ejecutar código JavaScript arbitrario en el navegador de otros usuarios. La página de inicio de sesión en /cgi/slogin.cgi sufre XSS reflejado debido al filtrado de entrada incorrecto del parámetro -tsetup+-uuser, que solo se puede explotar si el usuario de destino aún no ha iniciado sesión, lo que lo hace ideal para intentos de phishing en el formulario de inicio de sesión."
    }
  ],
  "lastModified": "2026-06-17T07:36:50.323",
  "sourceIdentifier": "551230f0-3615-47bd-b7cc-93e92e730bbf"
}