PT-2024-21695 · Toshiba · Toshiba Printers

Pierre Barre

·

Published

2024-06-14

·

Updated

2024-07-04

·

CVE-2024-27162

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Toshiba printers (affected versions not specified)
Description The issue concerns a web interface in Toshiba printers that loads a JavaScript file containing insecure codes, making it vulnerable to XSS attacks. This file is loaded inside all webpages provided by the printer, allowing an attacker to potentially steal the cookie of an admin user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-27162

Affected Products

Toshiba Printers