CVE-2024-36494

CVE-2024-36494: Reflected Cross Site Scripting

Vendor Image Access Gmbh
Product Scan2Net
Weakness CWE-79 · XSS
Published December 12, 2024
Last update November 3, 2025

CVSS base score

What the vulnerability does

01Description

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at /cgi/slogin.cgi suffers from XSS due to improper input filtering of the -tsetup+-uuser parameter, which can only be exploited if the target user is not already logged in. This makes it ideal for login form phishing attempts.

Key dates

02Disclosure timeline

December 12, 2024 CVE published
November 3, 2025 Record updated