← voltar
CVE-2024-29193

GHSL-2023-207 gotortc DOM-based Cross-site Scripting vulnerability

CVSS 6.1 MEDIUMEPSS 0.5%CWE-79
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.1EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
04 abr 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. The index page (`index.html`) shows the available streams by fetching the API in the client side. Then, it uses `Object.entries` to iterate over the result whose first item (`name`) gets appended using `innerHTML`. In the event of a victim visiting the server in question, their browser will execute the request against the go2rtc instance. After the request, the browser will be redirected to go2rtc, in which the XSS would be executed in the context of go2rtc’s origin. As of time of publication, no patch is available.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
AlexxIT · go2rtc

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →