CVE-2024-29882

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
28/03/2024
Last modified:
08/01/2026

Description

SRS is a simple, high-efficiency, real-time video server. SRS's `/api/v1/vhosts/vid-?callback=` endpoint didn't filter the callback function name which led to injecting malicious javascript payloads and executing XSS ( Cross-Site Scripting). This vulnerability is fixed in 5.0.210 and 6.0.121.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ossrs:simple_realtime_server:*:*:*:*:*:*:*:* 5.0.210 (excluding)
cpe:2.3:a:ossrs:simple_realtime_server:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.121 (excluding)