Vulnerability Details CVE-2024-8457
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.1%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2024-8457
-
cpe:2.3:h:planet:gs-4210-24p2s:3.0
-
cpe:2.3:h:planet:gs-4210-24pl4c:2.0
-
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*
-
cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*