MEDIUM
NewType WebEIP v3.0 - Reflected XSS
Published Oct 15, 2024
5.4
MEDIUMCVSS 3.1
EPSS 0.29%
Description
NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflected Cross-site Scripting (XSS) attack. The affected product is no longer maintained. It is recommended to upgrade to the new product.
Affected products
-
- Version 3.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The vendor has stated that WebEIP v3.0 has been released for over 15 years and is no longer supported or maintained. It is recommended to upgrade to the new WebEIP Pro product.
Weaknesses (1)
References (2)
- https://www.twcert.org.tw/en/cp-139-8135-ce1e6-2.html third-party-advisoryThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-8134-c476d-1.html third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-8135-ce1e6-2.html | third-party-advisoryThird Party Advisory | |
| https://www.twcert.org.tw/tw/cp-132-8134-c476d-1.html | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Oct 15, 2024
Updated Oct 15, 2024
Reserved Oct 15, 2024
Link CVE-2024-9969
CISA Vulnrichment
Updated Oct 15, 2024