CVE-2021-3441
MEDIUMHP OfficeJet 7110 Firmware >=2117a - Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2021-3441. PoCs published by Tyler Butler, tcbutler320.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in HP OfficeJet printers by sending a crafted XML payload via a PUT request to the ProductConfigDyn.xml endpoint. The payload injects a JavaScript alert into the DeviceLocation field, which is then stored and executed in the context of the printer's web interface.
Description
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).
Exploits (2)
This exploit demonstrates a stored XSS vulnerability in HP OfficeJet printers by sending a crafted XML payload via a PUT request to the ProductConfigDyn.xml endpoint. The payload injects a JavaScript alert into the DeviceLocation field, which is then stored and executed in the context of the printer's web interface.
This repository contains a Python tool designed to scan HP printers for indicators of compromise related to CVE-2021-3441, an XSS vulnerability in HP's embedded web server. It checks HTTP response headers and specific XML paths for suspicious characters that may indicate exploitation.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N