Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Antqt

#38230of 53,630
7.2Total CVSS
Vulnerabilities · 1
PT-2024-23106
7.2
2024-03-28
Srs · Srs · CVE-2024-29882
**Name of the Vulnerable Software and Affected Versions** SRS versions prior to 5.0.210 SRS versions prior to 6.0.121 **Description** The issue concerns SRS, a simple, high-efficiency, real-time video server. Specifically, the `/api/v1/vhosts/vid-<id>?callback=<payload>` endpoint did not filter the callback function name, leading to the injection of malicious JavaScript payloads and the execution of Cross-Site Scripting (XSS). **Recommendations** For versions prior to 5.0.210, update to version 5.0.210 or later. For versions prior to 6.0.121, update to version 6.0.121 or later.