CVE-2024-55545: Reflected Cross-Site Scripting
Published Dec 10, 2024
·Updated
Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.
Affected Software
3 affected components
ORing IAP-420<2.01e
All of the following
Oringnet Iap-420 Firmware<=2.01e
Oringnet Iap-420
Event History
Dec 10, 2024
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55545?
CVE-2024-55545 has a severity level that may allow attackers to exploit Cross-Site Scripting (XSS) vulnerabilities.
2
How do I fix CVE-2024-55545?
To fix CVE-2024-55545, ensure that the ORing IAP-420 software is updated to version 2.01f or later.
3
What versions of ORing IAP-420 are affected by CVE-2024-55545?
CVE-2024-55545 affects the ORing IAP-420 version 2.01e and below.
4
What type of vulnerability is CVE-2024-55545?
CVE-2024-55545 is classified as a Cross-Site Scripting (XSS) vulnerability due to missing input validation.
5
What can an attacker do with CVE-2024-55545?
An attacker exploiting CVE-2024-55545 can potentially execute malicious scripts in the context of the user's session.