seclists.org
http://seclists.org/fulldisclosure/2024/Jul/1 CVE-2024-27162
MEDIUM
DOM-based XSS
Record summary
CVE-2024-27162 has a selected CVSS score of 6.1 (medium).
Description
Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable to XSS and is loaded inside all the webpages provided by the printer. An attacker can steal the cookie of an admin user. As for the affected products/models/versions, see the reference URL.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 14, 2024 · Source: CVE List
Affected products and versions
Showing 12 of 51| Product | Source | Version range | Status |
|---|---|---|---|
Toshiba Tec e-Studio multi-function peripheral (MFP)Browse Toshiba Tec Corporation / Toshiba Tec e-Studio multi-function peripheral (MFP)Default status: unaffected | CVE List | see the reference URL | affected |
e-studio-2010-acBrowse toshibatec / e-studio-2010-acDefault status: unknown | CVE List | Through * | affected |
e-studio-2015-ncBrowse toshibatec / e-studio-2015-ncDefault status: unknown | CVE List | Through * | affected |
e-studio-2018_aBrowse toshibatec / e-studio-2018_aDefault status: unknown | CVE List | Through * | affected |
e-studio-2020_acBrowse toshibatec / e-studio-2020_acDefault status: unknown | CVE List | Through * | affected |
e-studio-2021_acBrowse toshibatec / e-studio-2021_acDefault status: unknown | CVE List | Through * | affected |
e-studio-2110-acBrowse toshibatec / e-studio-2110-acDefault status: unknown | CVE List | Through * | affected |
e-studio-2510-acBrowse toshibatec / e-studio-2510-acDefault status: unknown | CVE List | Through * | affected |
e-studio-2515-ncBrowse toshibatec / e-studio-2515-ncDefault status: unknown | CVE List | Through * | affected |
e-studio-2518_aBrowse toshibatec / e-studio-2518_aDefault status: unknown | CVE List | Through * | affected |
e-studio-2520_ncBrowse toshibatec / e-studio-2520_ncDefault status: unknown | CVE List | Through * | affected |
e-studio-2521_acBrowse toshibatec / e-studio-2521_acDefault status: unknown | CVE List | Through * | affected |
References
5jvn.jp
https://jvn.jp/en/vu/JVNVU97136265/index.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-27162 toshibatec.com
https://www.toshibatec.com/information/20240531_01.html toshibatec.com
https://www.toshibatec.com/information/pdf/information20240531_01.pdf