CVE Feed

    Dashboard / CVE / CVE-2024-29191

    CVE-2024-29191

    gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. The links page (`links.html`) appends the `src` GET parameter (`[0]`) in all of its links for 1-click previews. The context in which `src` is being appended is `innerHTML` (`[1]`), which will insert the text as HTML. Commit 3b3d5b033aac3a019af64f83dec84f70ed2c8aba contains a patch for the issue.

    Published:Apr 4, 2024
    Last Modified:Sep 2, 2025
    EPS:Apr 4, 2024
    EPSS Score:0.00139
    CVSS Score:6.1

    Affected Products

    Vendor
    Alexxit
    Product
    Go2rtc

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High