Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable to XSS and is loaded inside all the webpages provided by the printer. An attacker can steal the cookie of an admin user. As for the affected products/models/versions, see the reference URL.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Toshiba

Published: 2024-06-14T03:39:04.876Z

Updated: 2024-08-02T00:27:59.695Z

Reserved: 2024-02-21T02:11:59.651Z

Link: CVE-2024-27162

cve-icon Vulnrichment

Updated: 2024-08-02T00:27:59.695Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-14T04:15:31.783

Modified: 2024-07-04T05:15:13.443

Link: CVE-2024-27162

cve-icon Redhat

No data.