First published: Thu Sep 26 2024(Updated: )
Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logged-in user accesses a specific file, an arbitrary script may be executed on the web browser of the user.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Planex Cs-qr10 Firmware | ||
Planex Cs-qr10 | ||
All of | ||
Planex Cs-qr20 Firmware | ||
PLANEX CS-QR20 | ||
All of | ||
Planex Cs-qr22 Firmware | ||
Planex Cs-qr22 | ||
All of | ||
Planex Cs-qr220 Firmware | ||
Planex Cs-qr220 | ||
All of | ||
Planex Cs-qr300 Firmware | ||
Planex Cs-qr300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45836 is a cross-site scripting (XSS) vulnerability which can potentially allow attackers to execute arbitrary scripts in the user's web browser.
To mitigate CVE-2024-45836, update the firmware of the affected PLANEX COMMUNICATIONS network cameras to the latest version provided by the vendor.
CVE-2024-45836 affects various models of Planex network cameras including CS-QR10, CS-QR20, CS-QR22, CS-QR220, and CS-QR300.
CVE-2024-45836 may allow attackers to perform a cross-site scripting attack by executing arbitrary scripts on a user's web session.
Exploiting CVE-2024-45836 requires a logged-in user to access a specific file that triggers the vulnerability, making exploitation context-dependent.