CVE-2024-36498
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2024-36498 is a cross-site scripting (XSS) vulnerability affecting the "Edit Disclaimer Text" function of a specific configuration menu. This issue arises due to insufficient input sanitization. Attackers can exploit this flaw to inject and execute arbitrary Javascript in the browsers of affected users. The vulnerability is only accessible to Poweruser and Admin users, and is located at the URL <https://$SCANNER/cgi/admin.cgi?-rdisclaimer+-apre>. The executed Javascript payload will be run every time the ScanWizard is loaded, even in the Kiosk-mode browser. Although version 7.40 of the software includes a fix, it can be bypassed by URL-encoding the Javascript payload again.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.