CVE-2024-8457
30.09.2024, 08:15
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.
Vendor | Product | Version |
---|---|---|
planet | gs-4210-24p2s_firmware | 𝑥 < 3.305b240802 |
planet | gs-4210-24pl4c_firmware | 𝑥 < 2.305b240719 |
𝑥
= Vulnerable software versions