Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/49454 | Exploit |
| https://www.selea.com | Product |
| https://www.selea.com/product/ | Product |
| https://www.vulncheck.com/advisories/selea-targa-ip-camera-stored-cross-site-scripting-via-files-list | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5614.php | Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
Configuration 12 (hide)
|
History
23 Feb 2026, 19:00
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/49454 - Exploit | |
| References | () https://www.selea.com - Product | |
| References | () https://www.selea.com/product/ - Product | |
| References | () https://www.vulncheck.com/advisories/selea-targa-ip-camera-stored-cross-site-scripting-via-files-list - Third Party Advisory | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5614.php - Third Party Advisory | |
| CPE | cpe:2.3:h:selea:targa_704_tkm:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_710_inox_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:selea:carplateserver:4.013\(201105\):*:*:*:*:*:*:* cpe:2.3:h:selea:targa_semplice:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_512:-:*:*:*:*:*:*:* cpe:2.3:h:selea:izero_column_entry\/8:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_512_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:izero_box_full:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_750_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_504_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_504:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_704_ilb_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_750:-:*:*:*:*:*:*:* cpe:2.3:o:selea:izero_column_full\/8_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:selea:carplateserver:3.100\(200225\):*:*:*:*:*:*:* cpe:2.3:o:selea:izero_column_entry\/8_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_710_inox:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_704_tkm_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_704_ilb:-:*:*:*:*:*:*:* cpe:2.3:a:selea:carplateserver:3.005\(191206\):*:*:*:*:*:*:* cpe:2.3:o:selea:izero_box_full_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_semplice_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:selea:targa_805:-:*:*:*:*:*:*:* cpe:2.3:a:selea:carplateserver:3.005\(191112\):*:*:*:*:*:*:* cpe:2.3:h:selea:izero_column_full\/8:-:*:*:*:*:*:*:* cpe:2.3:o:selea:targa_805_firmware:-:*:*:*:*:*:*:* |
|
| First Time |
Selea izero Column Full\/8
Selea targa 750 Firmware Selea targa 750 Selea Selea izero Box Full Firmware Selea targa 504 Selea targa 710 Inox Selea targa Semplice Firmware Selea targa 704 Ilb Firmware Selea izero Column Full\/8 Firmware Selea targa 704 Tkm Selea targa 512 Selea targa 512 Firmware Selea targa 704 Ilb Selea targa Semplice Selea izero Box Full Selea targa 710 Inox Firmware Selea izero Column Entry\/8 Selea targa 504 Firmware Selea targa 805 Selea izero Column Entry\/8 Firmware Selea targa 805 Firmware Selea carplateserver Selea targa 704 Tkm Firmware |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
09 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 21:15
Updated : 2026-02-23 19:00
NVD link : CVE-2021-47729
Mitre link : CVE-2021-47729
CVE.ORG link : CVE-2021-47729
JSON object : View
Products Affected
selea
- targa_704_tkm_firmware
- targa_750
- izero_column_entry\/8
- targa_805_firmware
- targa_710_inox
- targa_704_tkm
- targa_512
- targa_805
- targa_semplice
- targa_704_ilb_firmware
- targa_704_ilb
- izero_box_full_firmware
- targa_512_firmware
- targa_semplice_firmware
- izero_column_entry\/8_firmware
- izero_column_full\/8_firmware
- izero_box_full
- targa_504_firmware
- targa_750_firmware
- targa_710_inox_firmware
- carplateserver
- targa_504
- izero_column_full\/8
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
