Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs.
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Link | Tags |
---|---|
https://jvn.jp/en/vu/JVNVU95063136/ | third party advisory |
https://global.sharp/products/copier/info/info_security_2024-10.html | vendor advisory |
https://www.toshibatec.com/information/20241025_01.html | vendor advisory |