There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.
History

Tue, 29 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Tue, 22 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Hikvision
Hikvision hikcentral Master
Weaknesses CWE-79
CPEs cpe:2.3:a:hikvision:hikcentral_master:*:*:*:*:lite:*:*:*
Vendors & Products Hikvision
Hikvision hikcentral Master
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 18 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Oct 2024 08:45:00 +0000

Type Values Removed Values Added
Description There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hikvision

Published: 2024-10-18T08:33:07.095Z

Updated: 2024-10-29T14:55:07.596Z

Reserved: 2024-09-25T06:22:37.960Z

Link: CVE-2024-47486

cve-icon Vulnrichment

Updated: 2024-10-18T14:36:28.474Z

cve-icon NVD

Status : Modified

Published: 2024-10-18T09:15:03.217

Modified: 2024-10-29T15:35:31.557

Link: CVE-2024-47486

cve-icon Redhat

No data.