CVE-2024-47549
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47549?
CVE-2024-47549 is categorized as a medium severity vulnerability due to its potential to allow cross-site scripting attacks through manipulated HTTP headers.
How do I fix CVE-2024-47549?
To mitigate CVE-2024-47549, update the affected Sharp and Toshiba Tec MFPs' firmware to the latest version provided by the manufacturer.
Which products are affected by CVE-2024-47549?
CVE-2024-47549 affects various Sharp and Toshiba Tec Multifunction Printers (MFPs), specifically those running specific firmware versions.
What type of vulnerability is CVE-2024-47549?
CVE-2024-47549 is a cross-site scripting (XSS) vulnerability related to improper processing of HTTP query parameters.
What are the potential impacts of CVE-2024-47549?
Exploiting CVE-2024-47549 may allow an attacker to execute malicious scripts in the context of a user's browser, potentially exposing sensitive information.