First published: Wed Feb 14 2024(Updated: )
Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Sharp Jh-rvb1 Firmware | <=b0.1.9.1 | |
Sharp Jh-rvb1 | ||
All of | ||
Sharp Jh-rv11 Firmware | <=b0.1.9.1 | |
Sharp Jh-rv11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23786 is classified as a moderate severity vulnerability due to its potential for unauthorized script execution.
To fix CVE-2024-23786, update the Energy Management Controller with the latest firmware version beyond b0.1.9.1.
CVE-2024-23786 affects users of the Sharp JH-RVB1 and JH-RV11 with firmware version b0.1.9.1 or earlier.
CVE-2024-23786 is a Cross-site scripting (XSS) vulnerability.
An attacker exploiting CVE-2024-23786 can execute arbitrary scripts on the web browser of users accessing the management page.