Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS via the error message for requesting non-existing page.
References
| Link | Resource |
|---|---|
| https://talosintelligence.com/vulnerability_reports/ | Third Party Advisory |
| https://www.geovision.com.tw/cyber_security.php | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-05-04 01:16
Updated : 2026-06-17 11:02
NVD link : CVE-2026-7371
Mitre link : CVE-2026-7371
CVE.ORG link : CVE-2026-7371
JSON object : View
Products Affected
geovision
- gv-lpc2011
- gv-lpc2211_firmware
- gv-lpc2011_firmware
- gv-lpc2211
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
