CVE-2024-36249

CVSS v3 Score
7.4
High

Vulnerability Description

Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be executed on the administrative page of the affected MFPs. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVSS:7.4(High)

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cro...

CWE-792016
CVSS:7.4(High)

Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network...

CWE-792019
CVSS:7.4(High)

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.

CWE-792019
CVSS:7.4(High)

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.

CWE-792019
CVSS:7.4(High)

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.

CWE-792019
CVSS:7.4(High)

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.

CWE-792019