CVE-2021-47729

MEDIUM
Published Dec 9, 2025 Modified Feb 23, 2026 CWE-79

Description

Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session.

CVSS v3.1 Score

5.4
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Weakness Type (CWE)

CWE-79 Cross-site Scripting (XSS)

Affected Products

Vendor Product
selea izero_box_full_firmware
selea izero_box_full
selea izero_column_entry\/8_firmware
selea izero_column_entry\/8
selea izero_column_full\/8_firmware
selea izero_column_full\/8
selea targa_504_firmware
selea targa_504
selea targa_512_firmware
selea targa_512
selea targa_704_ilb_firmware
selea targa_704_ilb
selea targa_704_tkm_firmware
selea targa_704_tkm
selea targa_710_inox_firmware
selea targa_710_inox
selea targa_750_firmware
selea targa_750
selea targa_805_firmware
selea targa_805
selea targa_semplice_firmware
selea targa_semplice
selea carplateserver
selea carplateserver
selea carplateserver
selea carplateserver

References

Frequently Asked Questions

What is CVE-2021-47729? +
Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session. It has a CVSS v3.1 base score of 5.4 (MEDIUM).
How severe is CVE-2021-47729? +
CVE-2021-47729 has a CVSS v3.1 score of 5.4 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2021-47729? +
CVE-2021-47729 affects products from selea, specifically: carplateserver, izero_box_full, izero_box_full_firmware, izero_column_entry\/8, izero_column_entry\/8_firmware, izero_column_full\/8, izero_column_full\/8_firmware, targa_504, targa_504_firmware, targa_512, targa_512_firmware, targa_704_ilb, targa_704_ilb_firmware, targa_704_tkm, targa_704_tkm_firmware, targa_710_inox, targa_710_inox_firmware, targa_750, targa_750_firmware, targa_805, targa_805_firmware, targa_semplice, targa_semplice_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2021-47729? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2021-47729 — free, no signup required.

Start Free Scan