VulnerabilityAnalyzed
CVE-2024-48870
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability.
MEDIUM 4.8EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- toshibatec/e-studio1058 firmware · toshibatec/e-studio1208 firmware · toshibatec/e-studio908 firmware · sharp/bp-90c70 firmware · sharp/bp-90c80 firmware · sharp/bp-70c65 firmware · sharp/bp-70c55 firmware · sharp/bp-70c45 firmware · sharp/bp-70c36 firmware · sharp/bp-70c31 firmware · sharp/bp-60c45 firmware · sharp/bp-60c36 firmware · sharp/bp-60c31 firmware · sharp/bp-50c65 firmware · sharp/bp-50c55 firmware · sharp/bp-50c45 firmware · sharp/bp-50c36 firmware · sharp/bp-50c31 firmware · sharp/bp-50c26 firmware · sharp/bp-55c26 firmware · +40 more
- Source
- vultures@jpcert.or.jp
References
- https://global.sharp/products/copier/info/info_security_2024-10.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU95063136/Third Party Advisory
- https://www.toshibatec.com/information/20241025_01.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.