### [CVE-2018-7827](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7827) ![](https://img.shields.io/static/v1?label=Product&message=Pelco%20Sarix%20Enhanced%20and%20Spectra%20Enhanced%2C%20Pelco%20Sarix%20Enhanced%201st%20generation%20and%20Spectra%20Enhanced%20PTZ&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Multiple%20Vulnerabilities&color=brighgreen) ### Description A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user’s browser session. ### POC #### Reference - https://www.schneider-electric.com/en/download/document/SEVD-2019-045-03/ - https://www.schneider-electric.com/en/download/document/SEVD-2019-045-03/ #### Github No PoCs found on GitHub currently.