CVE Published: 27/10/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: bosch |
Vendor: Bosch |
Product: VIDEOJET multi 4000 Status : PUBLISHED
CVE-2022-40183 Description
An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user.
Metrics
CVSS Version: 3.1 |
Base Score: 5.8 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L