- Description
- Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS via the error message for requesting non-existing page.
- Source
- 0df08a0e-a200-4957-9bb0-084f562506f9
- NVD status
- Analyzed
- Products
- gv-lpc2011_firmware, gv-lpc2211_firmware
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- 0df08a0e-a200-4957-9bb0-084f562506f9
- CWE-79
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-lpc2011_firmware:1.10:*:*:*:*:*:*:*",
"matchCriteriaId": "C1E349A9-4EEF-40B6-89A0-86242C2ADBC5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-lpc2011:-:*:*:*:*:*:*:*",
"matchCriteriaId": "87CE78D0-0894-451F-9A70-4F2A8062EC8A",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-lpc2211_firmware:1.10:*:*:*:*:*:*:*",
"matchCriteriaId": "0F3B818E-22D3-400A-AF2C-DEA66280464A",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-lpc2211:-:*:*:*:*:*:*:*",
"matchCriteriaId": "59F15521-B4F3-4CCA-8C03-0A4EA2864C6E",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]