Vulnerability Details CVE-2024-8457
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.7%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2024-8457
-
cpe:2.3:h:planet:gs-4210-24p2s:3.0
-
cpe:2.3:h:planet:gs-4210-24pl4c:2.0
-
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*
-
cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*