Vulnerability Details CVE-2021-47729
Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.2%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2021-47729
-
cpe:2.3:a:selea:carplateserver:3.005(191112)
-
cpe:2.3:a:selea:carplateserver:3.005(191206)
-
cpe:2.3:a:selea:carplateserver:3.100(200225)
-
cpe:2.3:a:selea:carplateserver:4.013(201105)
-
cpe:2.3:h:selea:izero_box_full:-
-
cpe:2.3:h:selea:izero_column_entry/8:-
-
cpe:2.3:h:selea:izero_column_full/8:-
-
cpe:2.3:h:selea:targa_504:-
-
cpe:2.3:h:selea:targa_512:-
-
cpe:2.3:h:selea:targa_704_ilb:-
-
cpe:2.3:h:selea:targa_704_tkm:-
-
cpe:2.3:h:selea:targa_710_inox:-
-
cpe:2.3:h:selea:targa_750:-
-
cpe:2.3:h:selea:targa_805:-
-
cpe:2.3:h:selea:targa_semplice:-
-
cpe:2.3:o:selea:izero_box_full_firmware:-
-
cpe:2.3:o:selea:izero_column_entry/8_firmware:-
-
cpe:2.3:o:selea:izero_column_full/8_firmware:-
-
cpe:2.3:o:selea:targa_504_firmware:-
-
cpe:2.3:o:selea:targa_512_firmware:-
-
cpe:2.3:o:selea:targa_704_ilb_firmware:-
-
cpe:2.3:o:selea:targa_704_tkm_firmware:-
-
cpe:2.3:o:selea:targa_710_inox_firmware:-
-
cpe:2.3:o:selea:targa_750_firmware:-
-
cpe:2.3:o:selea:targa_805_firmware:-
-
cpe:2.3:o:selea:targa_semplice_firmware:-