vendor:
Targa IP OCR-ANPR Camera
by:
LiquidWorm
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Targa IP OCR-ANPR Camera
Affected Version From: BLD201113005214
Affected Version To: BLD191021180140
Patch Exists: YES
Related CWE: CVE-2020-25862
CPE: h:selea:targa_ip_ocr-anpr_camera
Other Scripts:
N/A
Platforms Tested: None
2020
Selea Targa IP OCR-ANPR Camera – ‘files_list’ Remote Stored XSS
The application suffers from a stored XSS through a POST request. The issue is triggered when input passed to the 'files_list' parameter is not properly sanitized befoer being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Mitigation:
Upgrade to the latest version of the Selea Targa IP OCR-ANPR Camera.