Record summary

CVE-2023-45671 has a selected CVSS score of 4.7 (medium); EIP currently links 1 Nuclei template.

Description

Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site scripting vulnerability in any API endpoints reliant on the `/<camera_name>` base path as values provided for the path are not sanitized. Exploiting this vulnerability requires the attacker to both know very specific information about a user's Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to the internet (even with authentication); attacker knows the address of a user's Frigate instance; attacker crafts a specialized page which links to the user's Frigate instance; attacker finds a way to get an authenticated user to visit their specialized page and click the button/link. As the reflected values included in the URL are not sanitized or escaped, this permits execution arbitrary Javascript payloads. Version 0.13.0 Beta 3 contains a patch for this issue.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List< 0.13.0-beta3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMFrigate < 0.13.0 Beta 3 - Cross-Site ScriptingCVSS 4.7

Frigate is an open source network video recorder. Before version 0.13.0 Beta 3, there is a reflected cross-site scripting vulnerability in any API endpoints reliant on the `/<camera_name>` base path as values provided for the path are not sanitized. Exploiting this vulnerability requires the attacker to both know very specific information about a user's Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to the internet (even with authentication); attacker knows the address of a user's Frigate instance; attacker crafts a specialized page which links to the user's Frigate instance; attacker finds a way to get an authenticated user to visit their specialized page and click the button/link. As the reflected values included in the URL are not sanitized or escaped, this permits execution arbitrary Javascript payloads. Version 0.13.0 Beta 3 contains a patch for this issue.

Impact

Authenticated attackers can inject malicious JavaScript through unsanitized camera_name path values in API endpoints to execute attacks against Frigate users when they click specially crafted links.

Remediation

It has been fixed in version 0.13.0 Beta 3

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023frigatexssvuln
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:frigate:frigate:*:*:*:*:*:*:*:*
Shodan: title:"Frigate"
Shodan: http.title:"frigate"
FOFA: title="frigate"
Google: intitle:"frigate"

Source: ProjectDiscovery

References

2