Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-3850 PoC — Uniview NVR301-04S2-P4 跨站脚本漏洞

Source
Associated Vulnerability
Title:Uniview NVR301-04S2-P4 跨站脚本漏洞 (CVE-2024-3850)
Description:Uniview NVR301-04S2-P4是中国宇视科技(Uniview)公司的一个摄像机。 Uniview NVR301-04S2-P4存在跨站脚本漏洞,该漏洞源于容易受到反射型跨站脚本攻击(XSS)。
Description
Uniview NVR301-04S2-P4 contains a reflected cross-site scripting vulnerability via the PATH of LAPI. CISA and Uniview state that this vulnerability needs to be authenticated. This is incorrect. Any PATH payload can cause XSS. A submission to Mitre has been sent to update the verbiage in the finding as well as the CVSS score.
File Snapshot

id: CVE-2024-3850 info: name: Uniview NVR301-04S2-P4 - Cross-Site Scripting author: Bleron Rrus ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.