vendor:
OfficeJet 4630/7110 MYM1FN2025AR 2117A
by:
Tyler Butler
8,8
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: OfficeJet 4630/7110 MYM1FN2025AR 2117A
Affected Version From: HP OfficeJet 7110 Wide Format ePrinter
Affected Version To: HP Officejet 4630 e-All-in-One Printer series model number B4L03A
Patch Exists: YES
Related CWE: N/A
CPE: h:hp:officejet_4630_e-all-in-one_printer_series_model_number_b4l03a
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Mac, Windows
2021
HP OfficeJet 4630/7110 MYM1FN2025AR 2117A – Stored Cross-Site Scripting (XSS)
A stored cross-site scripting (XSS) vulnerability exists in HP OfficeJet 4630/7110 MYM1FN2025AR 2117A. An attacker can exploit this vulnerability by sending a malicious payload to the vulnerable device via a PUT request. The payload is then stored in the device's configuration file, which is accessible via a GET request. This allows an attacker to execute arbitrary JavaScript code in the context of the vulnerable device.
Mitigation:
HP has released a patch to address this vulnerability. Users should update their devices to the latest version of the firmware.