CVE Database
/

CVE-2024-36494

Back to search

CVE-2024-36494

Published: Dec 12, 2024

Modified: Nov 3, 2025

PUBLISHED

Description

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at /cgi/slogin.cgi suffers from XSS due to improper input filtering of the -tsetup+-uuser parameter, which can only be exploited if the target user is not already logged in. This makes it ideal for login form phishing attempts.

VendorProductVersions

Image Access GmbH

Scan2Net

affected
0 - < 7.42B

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now