First published: Tue Aug 20 2019(Updated: )
A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Androvideo Vd 1 | <=230 | |
Androvideo Vd 1 Firmware | ||
Geovision Gv-vr360 | <=1.10 | |
GeoVision | ||
Geovision Gv-vd8700 | <=1.01 | |
GeoVision |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13407 is classified as a high-severity vulnerability due to its ability to allow reflected cross-site scripting (XSS).
To fix CVE-2019-13407, update the affected Advan VD-1 firmware to a version that exceeds 230, ensuring proper input sanitization.
CVE-2019-13407 affects Advan VD-1 firmware versions up to 230 and specific firmware versions of Geovision products.
CVE-2019-13407 exploits XSS by returning a path error message from the cgibin/ssi.cgi resource without proper escaping of user input.
Manufacturers of the affected devices, such as Androvideo and Geovision, are responsible for providing security updates to mitigate CVE-2019-13407.