CVE-2024-47486

There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hikvision:hikcentral_master:*:*:*:*:lite:*:*:*

History

22 Oct 2024, 16:11

Type Values Removed Values Added
CWE CWE-79
References () https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-hikcentral-product-series/ - () https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-hikcentral-product-series/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:hikvision:hikcentral_master:*:*:*:*:lite:*:*:*
First Time Hikvision
Hikvision hikcentral Master

18 Oct 2024, 12:52

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad XSS en algunas versiones de HikCentral Master Lite. Si se aprovecha, un atacante podría inyectar scripts en determinadas páginas mediante la creación de datos maliciosos.

18 Oct 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-18 09:15

Updated : 2024-11-21 15:15


NVD link : CVE-2024-47486

Mitre link : CVE-2024-47486

CVE.ORG link : CVE-2024-47486


JSON object : View

Products Affected

hikvision

  • hikcentral_master
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')