Record summary

CVE-2024-3850 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.

Description

Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL that if clicked on could execute malicious JavaScript in their browser. This vulnerability also requires authentication before it can be exploited, so the scope and severity is limited. Also, even if JavaScript is executed, no additional benefits are obtained.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 12, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore NVR-B3801.20.17.240507affected

Nuclei templates

1
ProjectDiscoveryMEDIUMUniview NVR301-04S2-P4 - Cross-Site ScriptingCVSS 5.4

Uniview NVR301-04S2-P4 contains a reflected cross-site scripting vulnerability via the PATH of LAPI. CISA and Uniview state that this vulnerability needs to be authenticated. This is incorrect. Any PATH payload can cause XSS. A submission to Mitre has been sent to update the verbiage in the finding as well as the CVSS score.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.

Remediation

To fix this vulnerability, it is recommended to apply the latest patches or updates provided by the vendor.

WeaknessesCWE-79
AuthorsBleron Rrustemi, r3naissance
Template tagscvecve2024xssuniviewnvrvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:h:uniview:nvr301-04s2-p4:-:*:*:*:*:*:*:*
FOFA: title="NVR301-04-P4"

Source: ProjectDiscovery

References

3