Description
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.
Published: 2024-06-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upate to version 3.1.0.114 or later.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-29063 The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.
History

Fri, 16 Aug 2024 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Asus
Asus download Master
CPEs cpe:2.3:a:asus:download_master:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus download Master

Subscriptions

Asus Download Master
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-02T01:46:04.534Z

Reserved: 2024-03-29T07:18:19.359Z

Link: CVE-2024-31159

cve-icon Vulnrichment

Updated: 2024-06-14T18:14:43.414Z

cve-icon NVD

Status : Modified

Published: 2024-06-14T04:15:41.790

Modified: 2024-11-21T09:12:56.343

Link: CVE-2024-31159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses