CVE-2024-48870: XSS
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48870?
CVE-2024-48870 has been classified as a medium severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-48870?
To mitigate CVE-2024-48870, ensure that you update the firmware of affected Sharp and Toshiba Tec MFPs to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-48870?
CVE-2024-48870 affects certain models of Sharp and Toshiba Tec multifunction printers with specific firmware versions.
What type of vulnerability is CVE-2024-48870?
CVE-2024-48870 is a stored cross-site scripting (XSS) vulnerability due to improper input validation in URI data registration.
Can CVE-2024-48870 impact user data security?
Yes, if successfully exploited, CVE-2024-48870 can lead to unauthorized execution of malicious scripts on users' browsers, compromising their data security.