The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Aug 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Asus
Asus download Master |
|
CPEs | cpe:2.3:a:asus:download_master:*:*:*:*:*:*:*:* | |
Vendors & Products |
Asus
Asus download Master |
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-06-14T03:25:03.735Z
Updated: 2024-08-02T01:46:04.534Z
Reserved: 2024-03-29T07:18:19.359Z
Link: CVE-2024-31159
Vulnrichment
Updated: 2024-06-14T18:14:43.414Z
NVD
Status : Modified
Published: 2024-06-14T04:15:41.790
Modified: 2024-11-21T09:12:56.343
Link: CVE-2024-31159
Redhat
No data.