CVE-2024-31160

Severity
4.8MEDIUM
EPSS
0.2%
top 55.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 14
Latest updateOct 15

Description

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

NVDasus/download_master< 3.1.0.114
CVEListV5asus/download_masterearlier3.1.0.113

🔴Vulnerability Details

2
CVEList
ASUS Download Master - Stored XSS2024-06-14
GHSA
GHSA-xrch-m74q-rcf4: The parameter used in the certain page of ASUS Download Master is not properly filtered for user input2024-06-14

📋Vendor Advisories

4
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Installation (jQueryUI) — CVE-2022-311602024-10-15
Oracle
Oracle Oracle JD Edwards Risk Matrix: Web Runtime SEC (jQueryUI) — CVE-2022-311602024-07-15
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (jQueryUI) — CVE-2022-311602024-04-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Billing Care (jQueryUI) — CVE-2022-311602024-01-15
CVE-2024-31160 (MEDIUM CVSS 4.8) | The parameter used in the certain p | cvebase.io