An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HBosch Cpp13
HWBoschall versionsBosch Cpp13 Firmware
OSBoschall versionsBosch Cpp4
HWBoschall versionsBosch Cpp4 Firmware
OSBoschall versionsBosch Cpp6
HWBoschall versionsBosch Cpp6 Firmware
OSBoschall versionsBosch Cpp7
HWBoschall versionsBosch Cpp7.3
HWBoschall versionsBosch Cpp7.3 Firmware
OSBoschall versionsBosch Cpp7 Firmware
OSBoschall versions
Related vulnerabilities
Pominięcie uwierzytelniania w kamerach IP Bosch CPP6/CPP7
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administra...
A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an ...
In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP header...
An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting ...