CVE-2024-41910

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version of JavaScript used.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hp:poly_clariti_manager_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_clariti_manager:-:*:*:*:*:*:*:*

History

13 Aug 2024, 13:06

Type Values Removed Values Added
First Time Hp poly Clariti Manager Firmware
Hp
Hp poly Clariti Manager
References () https://support.hp.com/us-en/document/ish_11006981-11007005-16/hpsbpy03960 - () https://support.hp.com/us-en/document/ish_11006981-11007005-16/hpsbpy03960 - Vendor Advisory
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:h:hp:poly_clariti_manager:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_clariti_manager_firmware:*:*:*:*:*:*:*:*

08 Aug 2024, 18:15

Type Values Removed Values Added
Summary A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XXS vulnerabilities in the version of JavaScript used. A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version of JavaScript used.

06 Aug 2024, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-06 14:16

Updated : 2025-03-14 17:15


NVD link : CVE-2024-41910

Mitre link : CVE-2024-41910


JSON object : View

Products Affected

hp

  • poly_clariti_manager
  • poly_clariti_manager_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')