An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All other versions are not affected.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HBosch Cpp13
HWBoschall versionsBosch Cpp13 Firmware
OSBosch7.757.76Bosch Cpp6
HWBoschall versionsBosch Cpp6 Firmware
OSBosch7.627.707.72Bosch Cpp7
HWBoschall versionsBosch Cpp7.3
HWBoschall versionsBosch Cpp7.3 Firmware
OSBosch7.627.707.72Bosch Cpp7 Firmware
OSBosch7.627.707.72
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
Related vulnerabilities
CVE-2021-23847CRITICAL9.8PL ✓same product
Pominięcie uwierzytelniania w kamerach IP Bosch CPP6/CPP7
CVE-2023-39509HIGH7.2same product
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administra...
CVE-2021-23849HIGH7.5same product
A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an ...
CVE-2021-23853HIGH8.3same product
In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP header...
CVE-2021-23848HIGH8.3same product
An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-bas...