CVE-2024-47947 - CVE House
Back to Database
Status published Unknown CVE-2024-47947

Stored cross site scripting

Vulnerability Description

Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" function of the configuration menu is vulnerable to stored XSS. Only the users Poweruser and Admin can use this function which is available at the URL https://$SCANNER/cgi/admin.cgi?-rdisclaimer+-apre The stored Javascript payload will be executed every time the ScanWizard is loaded, even in the Kiosk-mode browser.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47947

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Daniel Hirschberger (SEC Consult Vulnerability Lab)
  • Tobias Niemann (SEC Consult Vulnerability Lab)

Affected Vendor

Image Access GmbH

View all reports →

Affected Software

Scan2Net
Vulnerable Versions:
0

Timeline

Official Publish: December 12th, 2024
Last Modified: November 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)