CVE-2024-45836: XSS
Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logged-in user accesses a specific file, an arbitrary script may be executed on the web browser of the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45836?
CVE-2024-45836 is a cross-site scripting (XSS) vulnerability which can potentially allow attackers to execute arbitrary scripts in the user's web browser.
How do I fix CVE-2024-45836?
To mitigate CVE-2024-45836, update the firmware of the affected PLANEX COMMUNICATIONS network cameras to the latest version provided by the vendor.
Which devices are affected by CVE-2024-45836?
CVE-2024-45836 affects various models of Planex network cameras including CS-QR10, CS-QR20, CS-QR22, CS-QR220, and CS-QR300.
What type of attack is possible due to CVE-2024-45836?
CVE-2024-45836 may allow attackers to perform a cross-site scripting attack by executing arbitrary scripts on a user's web session.
Is CVE-2024-45836 easy to exploit?
Exploiting CVE-2024-45836 requires a logged-in user to access a specific file that triggers the vulnerability, making exploitation context-dependent.