CVE-2021-45812: XSS
Published Dec 28, 2021
·Updated
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.
Affected Software
4 affected components
NUUO Nvrsolo Firmware=3.9.1
NUUO NVRsolo
All of the following
NUUO Nvrsolo Firmware=3.9.1
NUUO NVRsolo
Event History
Dec 28, 2021
CVE Published
via MITRE·02:26 PM
Data Sourced
via MITRE·02:26 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45812?
CVE-2021-45812 has a severity level that allows attackers to potentially hijack user sessions through XSS vulnerabilities.
2
How do I fix CVE-2021-45812?
To mitigate CVE-2021-45812, it is recommended to upgrade to the latest version of NUUO NVRsolo firmware.
3
What does CVE-2021-45812 affect?
CVE-2021-45812 affects NUUO Network Video Recorder NVRsolo firmware version 3.9.1.
4
What type of attack is associated with CVE-2021-45812?
CVE-2021-45812 is associated with a Cross Site Scripting (XSS) attack that can lead to session hijacking.
5
Who is impacted by CVE-2021-45812?
Users of NUUO Network Video Recorder NVRsolo firmware version 3.9.1 are primarily impacted by CVE-2021-45812.