Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-31160


The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks.


Published

2024-06-14T04:15:42.083

Last Modified

2024-11-21T09:12:56.480

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application asus download_master < 3.1.0.114 Yes

References