Description
gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. The links page (`links.html`) appends the `src` GET parameter (`[0]`) in all of its links for 1-click previews. The context in which `src` is being appended is `innerHTML` (`[1]`), which will insert the text as HTML. Commit 3b3d5b033aac3a019af64f83dec84f70ed2c8aba contains a patch for the issue.
Published: 2024-04-04
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2680 gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. The links page (`links.html`) appends the `src` GET parameter (`[0]`) in all of its links for 1-click previews. The context in which `src` is being appended is `innerHTML` (`[1]`), which will insert the text as HTML. Commit 3b3d5b033aac3a019af64f83dec84f70ed2c8aba contains a patch for the issue.
Github GHSA Github GHSA GHSA-wv8x-3w6r-6h7v gotortc Cross-site Scripting vulnerability
History

Tue, 02 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Alexxit
Alexxit go2rtc
CPEs cpe:2.3:a:alexxit:go2rtc:*:*:*:*:*:*:*:*
Vendors & Products Alexxit
Alexxit go2rtc

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T01:10:55.432Z

Reserved: 2024-03-18T17:07:00.094Z

Link: CVE-2024-29191

cve-icon Vulnrichment

Updated: 2024-08-02T01:10:55.432Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-04T15:15:39.043

Modified: 2025-09-02T15:24:33.513

Link: CVE-2024-29191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses