Vulnerability CVE-2024-8457


Published: 2024-09-30

Description:
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://www.twcert.org.tw/tw/cp-132-8063-01634-1.html
https://www.twcert.org.tw/en/cp-139-8064-70255-2.html

Copyright 2026, cxsecurity.com

 

Back to Top