Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-3850

Опубликовано: 10 июн. 2024
Источник: nvd
CVSS3: 5.4
EPSS Средний

Описание

Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL that if clicked on could execute malicious JavaScript in their browser. This vulnerability also requires authentication before it can be exploited, so the scope and severity is limited. Also, even if JavaScript is executed, no additional benefits are obtained.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:uniview:nvr301-04s2-p4_firmware:*:*:*:*:*:*:*:*
Версия до nvr-b3801.20.17.240507 (исключая)
cpe:2.3:h:uniview:nvr301-04s2-p4:-:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.11904
Средний

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
больше 1 года назад

Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL that if clicked on could execute malicious JavaScript in their browser. This vulnerability also requires authentication before it can be exploited, so the scope and severity is limited. Also, even if JavaScript is executed, no additional benefits are obtained.

EPSS

Процентиль: 94%
0.11904
Средний

5.4 Medium

CVSS3

Дефекты

CWE-79