vendor:
NVR304-S-P
by:
Luis Martinez
4.3
CVSS
MEDIUM
Reflected Cross-Site Scripting (XSS)
79
CWE
Product Name: NVR304-S-P
Affected Version From: NVR304-16EP
Affected Version To: NVR304-16EP
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro 21H2 x64 es - Firefox 91.6.0esr
2022
Network Video Recorder NVR304-16EP – Reflected Cross-Site Scripting (XSS) (Unauthenticated)
A reflected cross-site scripting (XSS) vulnerability exists in Network Video Recorder NVR304-16EP, which allows an unauthenticated attacker to inject arbitrary web script or HTML via the 'LAPI/V1.0/System/Security/Login/' parameter.
Mitigation:
Input validation should be used to prevent XSS attacks. Sanitize user input and output to prevent malicious code from being executed.