The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Aug 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Asus
Asus download Master |
|
CPEs | cpe:2.3:a:asus:download_master:*:*:*:*:*:*:*:* | |
Vendors & Products |
Asus
Asus download Master |
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-06-14T03:41:21.402Z
Updated: 2024-08-02T01:46:04.470Z
Reserved: 2024-03-29T07:18:19.359Z
Link: CVE-2024-31160
Vulnrichment
Updated: 2024-07-19T18:45:30.678Z
NVD
Status : Modified
Published: 2024-06-14T04:15:42.083
Modified: 2024-11-21T09:12:56.480
Link: CVE-2024-31160
Redhat
No data.