"value":"Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability.\r\nIf crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"Cross-site scripting (XSS)",
"cweId":"CWE-79"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Toshiba Tec Corporation",
"product":{
"product_data":[
{
"product_name":"e-STUDIO 908",
"version":{
"version_data":[
{
"version_affected":"=",
"version_value":"T2.12.h3.00 and earlier versions"
}
]
}
},
{
"product_name":"e-STUDIO 1058",
"version":{
"version_data":[
{
"version_affected":"=",
"version_value":"T1.01.h4.00 and earlier versions"
}
]
}
},
{
"product_name":"e-STUDIO 1208",
"version":{
"version_data":[
{
"version_affected":"=",
"version_value":"T1.01.h4.00 and earlier versions"
}
]
}
}
]
}
},
{
"vendor_name":"Sharp Corporation",
"product":{
"product_data":[
{
"product_name":"Sharp Digital Full-color MFPs and Monochrome MFPs",
"version":{
"version_data":[
{
"version_affected":"=",
"version_value":"see the information provided by Sharp Corporation"