CVE-2024-48870
https://notcve.org/view.php?id=CVE-2024-48870
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users. • https://jvn.jp/en/vu/JVNVU95063136 https://global.sharp/products/copier/info/info_security_2024-10.html https://www.toshibatec.com/information/20241025_01.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-47801
https://notcve.org/view.php?id=CVE-2024-47801
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. • https://jvn.jp/en/vu/JVNVU95063136 https://global.sharp/products/copier/info/info_security_2024-10.html https://www.toshibatec.com/information/20241025_01.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-47549
https://notcve.org/view.php?id=CVE-2024-47549
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. • https://jvn.jp/en/vu/JVNVU95063136 https://global.sharp/products/copier/info/info_security_2024-10.html https://www.toshibatec.com/information/20241025_01.html • CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax •
CVE-2024-47406
https://notcve.org/view.php?id=CVE-2024-47406
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability. • https://jvn.jp/en/vu/JVNVU95063136 https://global.sharp/products/copier/info/info_security_2024-10.html https://www.toshibatec.com/information/20241025_01.html • CWE-288: Authentication Bypass Using an Alternate Path or Channel •
CVE-2024-47005
https://notcve.org/view.php?id=CVE-2024-47005
Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs. • https://jvn.jp/en/vu/JVNVU95063136 https://global.sharp/products/copier/info/info_security_2024-10.html https://www.toshibatec.com/information/20241025_01.html • CWE-749: Exposed Dangerous Method or Function •