CVE-2024-55546: Stored Cross-Site Scripting
Published Dec 10, 2024
·Updated
Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.
Affected Software
3 affected components
ORing IAP-420<2.01e
All of the following
Oringnet Iap-420 Firmware<=2.01e
Oringnet Iap-420
Event History
Dec 10, 2024
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55546?
CVE-2024-55546 has been classified as a high-severity vulnerability due to its potential for stored Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2024-55546?
To fix CVE-2024-55546, users should upgrade to a version of the ORing IAP-420 firmware that is greater than 2.01e.
3
What versions of ORing IAP-420 are affected by CVE-2024-55546?
CVE-2024-55546 affects ORing IAP-420 version 2.01e and all previous versions.
4
What type of vulnerability is CVE-2024-55546?
CVE-2024-55546 is a Stored Cross-Site Scripting (XSS) vulnerability stemming from missing input validation.
5
What can attackers do with CVE-2024-55546?
Attackers exploiting CVE-2024-55546 can execute malicious scripts in the context of the user's session, potentially leading to data theft or unauthorized actions.