Description
Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Model: iZero
Firmware: BLD201113005214
CPS: 4.013(201105)
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/49454 (ExploitDB-49454)
www.selea.com (Selea s.r.l. Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5614.php (Zero Science Lab Disclosure (ZSL-2021-5614))
www.selea.com/product/ (Selea Targa IP OCR-ANPR Camera Product Page)
www.vulncheck.com/...red-cross-site-scripting-via-files-list (VulnCheck Advisory: Selea Targa IP Camera Stored Cross-Site Scripting via Files List)