CVE-2024-8457

Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:*

History

04 Oct 2024, 14:45

Type Values Removed Values Added
References () https://www.twcert.org.tw/en/cp-139-8064-70255-2.html - () https://www.twcert.org.tw/en/cp-139-8064-70255-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-8063-01634-1.html - () https://www.twcert.org.tw/tw/cp-132-8063-01634-1.html - Third Party Advisory
First Time Planet gs-4210-24pl4c Firmware
Planet gs-4210-24p2s
Planet gs-4210-24pl4c
Planet gs-4210-24p2s Firmware
Planet
CPE cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:*
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*

30 Sep 2024, 12:45

Type Values Removed Values Added
Summary
  • (es) Ciertos modelos de conmutadores de PLANET Technology tienen una aplicación web que no valida correctamente parámetros específicos, lo que permite que usuarios autenticados remotos con privilegios de administrador inyecten JavaScript arbitrario, lo que genera un ataque XSS almacenado.

30 Sep 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-30 08:15

Updated : 2024-10-04 14:45


NVD link : CVE-2024-8457

Mitre link : CVE-2024-8457

CVE.ORG link : CVE-2024-8457


JSON object : View

Products Affected

planet

  • gs-4210-24pl4c_firmware
  • gs-4210-24pl4c
  • gs-4210-24p2s
  • gs-4210-24p2s_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')