First published: Fri Jun 14 2024(Updated: )
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
ASUS Download Master | <3.1.0.114 |
Update to version 3.1.0.114 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31160 is considered a high severity vulnerability due to its potential for remote exploitation.
To mitigate CVE-2024-31160, users should update ASUS Download Master to version 3.1.0.114 or later.
CVE-2024-31160 is a Stored Cross-site Scripting (XSS) vulnerability.
CVE-2024-31160 affects users of ASUS Download Master versions below 3.1.0.114.
Yes, CVE-2024-31160 can be exploited remotely by an attacker with administrative privileges.