CVE-2024-36494

D

ue to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at /cgi/slogin.cgi suffers from XSS due to improper input filtering of the -tsetup+-uuser parameter, which can only be exploited if the target user is not already logged in. This makes it ideal for login form phishing attempts.

Configurations

No configuration.

History

03 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Dec/2 -

12 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 13:15

Updated : 2025-11-03 22:16


NVD link : CVE-2024-36494

Mitre link : CVE-2024-36494

CVE.ORG link : CVE-2024-36494


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')