Description
RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details.
No analysis available yet.
Remediation
Vendor Solution
The manufacturer recommends upgrading RhinOS to the most recent version (see References).
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46631 | RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details. |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 05 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Saltos
Saltos rhinos |
|
| CPEs | cpe:2.3:a:saltos:rhinos:3.0:1190:*:*:*:*:*:* | |
| Vendors & Products |
Saltos
Saltos rhinos |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T21:11:12.697Z
Reserved: 2024-05-27T07:26:28.143Z
Link: CVE-2024-5409
Updated: 2024-08-01T21:11:12.697Z
Status : Analyzed
Published: 2024-05-27T13:15:09.040
Modified: 2025-06-05T15:31:08.950
Link: CVE-2024-5409
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD