CVE-2024-47801: XSS
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47801?
CVE-2024-47801 is categorized as a reflected cross-site scripting (XSS) vulnerability which is considered high severity due to the potential for exploitation via crafted URLs.
How do I fix CVE-2024-47801?
To mitigate CVE-2024-47801, users should update the firmware of the affected Sharp and Toshiba Tec MFPs to the latest version that addresses this vulnerability.
What products are affected by CVE-2024-47801?
CVE-2024-47801 affects various Sharp and Toshiba Tec multifunction printers (MFPs) including specific models such as the Sharp Mx series and Toshiba Tec e-Studio series.
How can attackers exploit CVE-2024-47801?
Attackers can exploit CVE-2024-47801 by sending crafted HTTP requests to the vulnerable products, which can execute malicious scripts in users' web browsers.
Is there a patch available for CVE-2024-47801?
Yes, vendors have released firmware updates that serve as patches to fix the vulnerability associated with CVE-2024-47801.