CVE-2024-47486

T

here is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.

Configurations

Configuration 1 (hide)

cpe:2.3:a:hikvision:hikcentral_master:*:*:*:*:lite:*:*:*

History

22 Oct 2024, 16:11

Type Values Removed Values Added
CPE cpe:2.3:a:hikvision:hikcentral_master:*:*:*:*:lite:*:*:*
References () https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-hikcentral-product-series/ - () https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-hikcentral-product-series/ - Vendor Advisory
First Time Hikvision hikcentral Master
Hikvision
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

18 Oct 2024, 12:52

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad XSS en algunas versiones de HikCentral Master Lite. Si se aprovecha, un atacante podría inyectar scripts en determinadas páginas mediante la creación de datos maliciosos.

18 Oct 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-18 09:15

Updated : 2024-11-21 15:15


NVD link : CVE-2024-47486

Mitre link : CVE-2024-47486

CVE.ORG link : CVE-2024-47486


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')