CVE-2024-38380

This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser session.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-261-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:millbeckcommunications:proroute_h685t-w_firmware:3.2.334:*:*:*:*:*:*:*
cpe:2.3:h:millbeckcommunications:proroute_h685t-w:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-17 18:15

Updated : 2024-10-02 14:22


NVD link : CVE-2024-38380

Mitre link : CVE-2024-38380

CVE.ORG link : CVE-2024-38380


JSON object : View

Products Affected

millbeckcommunications

  • proroute_h685t-w_firmware
  • proroute_h685t-w
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')