CVE-2022-33119: XSS
Published Jun 21, 2022
·Updated
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.
Affected Software
2 affected components
NUUO Nvrsolo Firmware=03.06.02
NUUO NVRsolo
Event History
Jun 21, 2022
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-33119?
CVE-2022-33119 is classified as a moderate severity reflected cross-site scripting vulnerability.
2
How do I fix CVE-2022-33119?
To fix CVE-2022-33119, update NUUO Network Video Recorder NVRsolo to a patched version beyond 03.06.02.
3
What types of attacks can be performed using CVE-2022-33119?
Exploitation of CVE-2022-33119 can lead to injection of malicious scripts that may steal session cookies or redirect users.
4
Who is affected by CVE-2022-33119?
CVE-2022-33119 affects users running NUUO Network Video Recorder NVRsolo firmware version 03.06.02.
5
What is reflected cross-site scripting as it relates to CVE-2022-33119?
Reflected cross-site scripting in CVE-2022-33119 allows attackers to execute arbitrary JavaScript in the context of the victim's browser when they access a malicious link.