VulnerabilityModified
CVE-2009-4608
Cross-site scripting (XSS) vulnerability in Canon IT Solutions Inc.
MEDIUM 4.3EPSS 1.80%
Does this matter?
Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Canon IT Solutions Inc. ACCESSGUARDIAN 3.0.14 and earlier, and 3.5.6 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to authentication.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- canon-its/accessguardian
- Source
- cve@mitre.org
References
- http://canon-its.jp/guardian/topics/200910ag.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN33822756/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000066.htmlThird Party Advisory, VDB Entry
- http://osvdb.org/59058Broken Link
- http://secunia.com/advisories/37045Third Party Advisory
- http://www.vupen.com/english/advisories/2009/2973Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53822Third Party Advisory, VDB Entry
- http://canon-its.jp/guardian/topics/200910ag.htmlVendor Advisory
- http://jvn.jp/en/jp/JVN33822756/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000066.htmlThird Party Advisory, VDB Entry
- http://osvdb.org/59058Broken Link
- http://secunia.com/advisories/37045Third Party Advisory
- http://www.vupen.com/english/advisories/2009/2973Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53822Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.