CVE-2024-36392: MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published Jun 2, 2024
·Updated
MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
3 affected components
Milesight DeviceHub
All of the following
Milesight DeviceHub=3.0.1-r1
Ubuntu=20.04
Event History
Jun 2, 2024
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36392?
CVE-2024-36392 has a high severity rating due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2024-36392?
To fix CVE-2024-36392, ensure that input validation and output encoding are properly implemented in the MileSight DeviceHub application.
3
What type of vulnerability is CVE-2024-36392?
CVE-2024-36392 is a Cross-site Scripting (XSS) vulnerability, categorized under CWE-79.
4
Which software is affected by CVE-2024-36392?
CVE-2024-36392 affects the MileSight DeviceHub software.
5
What are the risks associated with CVE-2024-36392?
The risks associated with CVE-2024-36392 include the potential for unauthorized actions on behalf of users and the exposure of sensitive information.