CVE-2024-36494: Reflected Cross Site Scripting

0.0 CVSS

Description

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at /cgi/slogin.cgi suffers from XSS due to improper input filtering of the -tsetup+-uuser parameter, which can only be exploited if the target user is not already logged in. This makes it ideal for login form phishing attempts.

Classification

CVE ID: CVE-2024-36494

CVSS Base Severity: LOW

CVSS Base Score: 0.0

Affected Products

Vendor: Image Access GmbH

Product: Scan2Net

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://r.sec-consult.com/imageaccess
https://www.imageaccess.de/?page=SupportPortal&lang=en

Timeline