Vulnerability Description
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nuuo | Nvrsolo Firmware | 3.9.1 |
| Nuuo | Nvrsolo | - |
Related Weaknesses (CWE)
References
- https://drive.google.com/drive/folders/18YCKzFnS5CZRmzgcwc8g7jvLpmqgy68B?usp=shaExploitThird Party Advisory
- https://drive.google.com/drive/folders/18YCKzFnS5CZRmzgcwc8g7jvLpmqgy68B?usp=shaExploitThird Party Advisory
FAQ
What is CVE-2021-45812?
CVE-2021-45812 is a vulnerability with a CVSS score of 6.1 (MEDIUM). NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to ses...
How severe is CVE-2021-45812?
CVE-2021-45812 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45812?
Check the references section above for vendor advisories and patch information. Affected products include: Nuuo Nvrsolo Firmware, Nuuo Nvrsolo.