PT-2020-2445 · Unknown · Sinvr 3 Video Server+2

Published

2020-03-10

·

Updated

2024-01-09

·

CVE-2019-19293

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Control Center Server (CCS) versions prior to V1.5.0 SiNVR 3 Central Control Server (all versions) SiNVR 3 Video Server (all versions)
Description A reflected Cross-site Scripting (XSS) vulnerability has been identified in the web interface of the Control Center Server (CCS) and SiNVR 3 Central Control Server. This vulnerability could allow an unauthenticated remote attacker to steal sensitive data or execute administrative actions on behalf of a legitimate administrator of the CCS web interface. The issue is related to the lack of input data sanitization, which may enable a remote attacker to gain unauthorized access to protected information or perform arbitrary actions on the vulnerable device.
Recommendations For Control Center Server (CCS) versions prior to V1.5.0, update to version V1.5.0 or later to resolve the issue. For SiNVR 3 Central Control Server and SiNVR 3 Video Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the web interface of the Control Center Server to minimize the risk of exploitation.

XSS

Weakness Enumeration

Related Identifiers

BDU:2020-02455
CVE-2019-19293

Affected Products

Control Center Server
Sinvr 3 Central Control Server
Sinvr 3 Video Server