RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details.
Fixes

Solution

The manufacturer recommends upgrading RhinOS to the most recent version (see References).


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00083}

epss

{'score': 0.00128}


Thu, 05 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Saltos
Saltos rhinos
CPEs cpe:2.3:a:saltos:rhinos:3.0:1190:*:*:*:*:*:*
Vendors & Products Saltos
Saltos rhinos

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T21:11:12.697Z

Reserved: 2024-05-27T07:26:28.143Z

Link: CVE-2024-5409

cve-icon Vulnrichment

Updated: 2024-08-01T21:11:12.697Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-27T13:15:09.040

Modified: 2025-06-05T15:31:08.950

Link: CVE-2024-5409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.