Vulnerabilities > Sharp > BP 30M35T Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-25 CVE-2024-45842 Path Traversal vulnerability in multiple products
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests.
network
low complexity
toshibatec sharp CWE-22
5.3
2024-10-25 CVE-2024-47549 Improper Encoding or Escaping of Output vulnerability in multiple products
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.
network
low complexity
toshibatec sharp CWE-116
6.1
2024-10-25 CVE-2024-47801 Cross-site Scripting vulnerability in multiple products
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.
network
low complexity
toshibatec sharp CWE-79
6.1
2024-10-25 CVE-2024-48870 Cross-site Scripting vulnerability in multiple products
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users.
network
low complexity
toshibatec sharp CWE-79
4.8