vendor:
NVR301-04S2-P4
by:
Bleron Rrustemi
7.5
CVSS
HIGH
Reflected Cross-Site Scripting (XSS)
79
CWE
Product Name: NVR301-04S2-P4
Affected Version From: NVR-B3801.20.15.200829
Affected Version To: NVR301-04S2-P4
Patch Exists: NO
Related CWE:
CPE: o:uniview:nvr301-04s2-p4
Platforms Tested: Windows 10 Enterprise LTSC 64, Firefox 106.0.5 (64-bit)
2022
Uniview NVR301-04S2-P4 – Reflected Cross-Site Scripting (XSS)
The Uniview NVR301-04S2-P4 device is vulnerable to reflected cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability by injecting malicious code into a crafted URL, which will be executed when accessed by a victim user.
Mitigation:
To mitigate this vulnerability, the vendor should release a security patch that properly sanitizes user input to prevent the execution of malicious code. Additionally, users are advised to avoid accessing untrusted URLs or clicking on suspicious links.