Cross-site Scripting Vulnerability in Affected Web Applications
CVE-2024-47917

7.5HIGH

Key Information:

Vendor

Mobotix

Status
Vendor
CVE Published:
30 December 2024

What is CVE-2024-47917?

The vulnerability allows attackers to exploit improper neutralization of input during web page generation, enabling cross-site scripting (XSS) attacks. This issue arises when web applications fail to adequately sanitize user input, letting malicious scripts be executed in the context of the user's session. Successful exploitation can lead to unauthorized access to sensitive information, session hijacking, and defacement of the web application, making it crucial for organizations to implement robust input validation and sanitation mechanisms.

Affected Version(s)

CCTV FW All versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Moriel Harush, Dudu Moyal - Peer Security LTD
.