Vulnerability CVE-2024-9969


Published: 2024-10-15

Description:
NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflected Cross-site Scripting (XSS) attack. The affected product is no longer maintained. It is recommended to upgrade to the new product.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://www.twcert.org.tw/tw/cp-132-8134-c476d-1.html
https://www.twcert.org.tw/en/cp-139-8135-ce1e6-2.html

Copyright 2024, cxsecurity.com

 

Back to Top