Multiple reflected cross-site scripting (xss)...
High severity
Unreviewed
Published
May 4, 2026
to the GitHub Advisory Database
•
Updated May 4, 2026
Description
Published by the National Vulnerability Database
May 4, 2026
Published to the GitHub Advisory Database
May 4, 2026
Last updated
May 4, 2026
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS via the error message for requesting non-existing page.
References