VYPR
High severity7.4NVD Advisory· Published May 4, 2026· Updated May 5, 2026

CVE-2026-7371

CVE-2026-7371

Description

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. Reflected XXS via the error message for requesting non-existing page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:o:geovision:gv-lpc2011_firmware:1.10:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:geovision:gv-lpc2011_firmware:1.10:*:*:*:*:*:*:*
    • cpe:2.3:o:geovision:gv-lpc2211_firmware:1.10:*:*:*:*:*:*:*
  • Range: = 1.10

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.