S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Feb 26, 2024

CVE-2023-45671 Scanner

CVE-2023-45671 scanner - Cross-Site Scripting (XSS) vulnerability in Frigate

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-45671
4.7
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site scripting vulnerability in any API endpoints reliant on the `/<camera_name>` base path as values provided for the path are not sanitized. Exploiting this vulnerability requires the attacker to both know very specific information about a user's Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to the internet (even with authentication); attacker knows the address of a user's Frigate instance; attacker crafts a specialized page which links to the user's Frigate instance; attacker finds a way to get an authenticated user to visit their specialized page and click the button/link. As the reflected values included in the URL are not sanitized or escaped, this permits execution arbitrary Javascript payloads. Version 0.13.0 Beta 3 contains a patch for this issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
frigateby blakeblackshear
< 0.13.0-beta3
Updated Aug 22, 2026View on NVD →
Detail

Vulnerability Overview

Frigate versions prior to 0.13.0 Beta 3 are susceptible to a reflected XSS attack via API endpoints that use the /<camera_name> base path. This vulnerability arises because the application does not properly sanitize user-supplied input in the URL path, allowing attackers to embed malicious scripts.

Vulnerability Details

This XSS vulnerability is exploitable when Frigate is publicly accessible, and the attacker can trick an authenticated user into clicking a specially crafted link. The lack of input sanitization allows the attacker to inject and execute arbitrary JavaScript code in the user's browser session.

Possible Effects

  • Execution of unauthorized JavaScript on the user's browser.
  • Potential theft of sensitive information from authenticated sessions.
  • Manipulation of the user interface to deceive users.

Why Choose S4E

S4E provides a robust platform to identify and mitigate vulnerabilities in real-time. With our scanner:

  • You gain comprehensive insights into potential security threats.
  • We offer detailed recommendations for swift and effective remediation.
  • Enjoy peace of mind with ongoing support and updates to safeguard your systems.

References

Solution Advice
  • Immediate Update: Upgrade Frigate to version 0.13.0 Beta 3 or later to resolve the vulnerability.
  • Limit Exposure: Avoid exposing Frigate to the public internet when possible.
  • Educate Users: Inform users about the risks of clicking on unknown links and educate them on recognizing phishing attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-45671 scanner - Cross-Site Scripting (XSS) vulnerability in Frigate S4E