Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update SmartRobot to version v7.1.0 or later, or contact the vendor for patch recommendations.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49408 | SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting attacks. |
Tue, 17 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:intumit:smartrobot_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:a:intumit:smartrobot:*:*:*:*:*:*:*:* |
| Vendors & Products |
Intumit smartrobot Firmware
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Sep 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Intumit
Intumit smartrobot Intumit smartrobot Firmware |
|
| CPEs | cpe:2.3:h:intumit:smartrobot:-:*:*:*:*:*:*:* cpe:2.3:o:intumit:smartrobot_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Intumit
Intumit smartrobot Intumit smartrobot Firmware |
Mon, 16 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Sep 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting attacks. | |
| Title | INTUMIT SmartRobot - Cross-site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T13:06:09.757Z
Reserved: 2024-09-13T09:43:44.404Z
Link: CVE-2024-8776
Updated: 2024-09-16T13:06:03.061Z
Status : Analyzed
Published: 2024-09-16T06:15:11.023
Modified: 2026-03-17T19:03:05.877
Link: CVE-2024-8776
No data.
OpenCVE Enrichment
No data.
EUVD