5.1
CVE-2022-40184
- EPSS 0.24%
- Veröffentlicht 27.10.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:21:01
- Quelle psirt@bosch.com
- CVE-Watchlists
- Unerledigt
Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET multi 4000 allows an attacker with administrative credentials to store JavaScript code which will be executed for all administrators accessing the same configuration option.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bosch ≫ Videojet Multi 4000 Firmware Version <= 6.31.0010
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.468 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.8 | 1.7 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
|
| psirt@bosch.com | 5.1 | 1 | 3.7 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.