Record summary

CVE-2024-27162 has a selected CVSS score of 6.1 (medium).

Description

Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable to XSS and is loaded inside all the webpages provided by the printer. An attacker can steal the cookie of an admin user. As for the affected products/models/versions, see the reference URL.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 14, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 51
ProductSourceVersion rangeStatus

Default status: unaffected

CVE Listsee the reference URLaffected

Default status: unknown

CVE ListThrough *affected

Default status: unknown

CVE ListThrough *affected

Default status: unknown

CVE ListThrough *affected

Default status: unknown

CVE ListThrough *affected

Default status: unknown

CVE ListThrough *affected

Default status: unknown

CVE ListThrough *affected

Default status: unknown

CVE ListThrough *affected

Default status: unknown

CVE ListThrough *affected

Default status: unknown

CVE ListThrough *affected

Default status: unknown

CVE ListThrough *affected

Default status: unknown

CVE ListThrough *affected

References

5