CVE-2024-3850
Uniview NVR301-04S2-P4 Cross-site Scripting
Record summary
CVE-2024-3850 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.
Description
Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL that if clicked on could execute malicious JavaScript in their browser. This vulnerability also requires authentication before it can be exploited, so the scope and severity is limited. Also, even if JavaScript is executed, no additional benefits are obtained.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 12, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
NVR301-04S2-P4Browse Uniview / NVR301-04S2-P4Default status: unaffected | CVE List | Before NVR-B3801.20.17.240507 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMUniview NVR301-04S2-P4 - Cross-Site ScriptingCVSS 5.4
Uniview NVR301-04S2-P4 contains a reflected cross-site scripting vulnerability via the PATH of LAPI. CISA and Uniview state that this vulnerability needs to be authenticated. This is incorrect. Any PATH payload can cause XSS. A submission to Mitre has been sent to update the verbiage in the finding as well as the CVSS score.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.
Remediation
To fix this vulnerability, it is recommended to apply the latest patches or updates provided by the vendor.
Source: ProjectDiscovery