CVE-2015-2883: XSS
Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to deviceSettings.php or shareDevice.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2883?
CVE-2015-2883 is classified as a medium severity vulnerability due to its potential impact on the confidentiality of user data.
How do I fix CVE-2015-2883?
To fix CVE-2015-2883, update the Philips In.Sight B120/37 firmware to the latest version provided by Philips that addresses this XSS vulnerability.
What effect does CVE-2015-2883 have on my device?
CVE-2015-2883 allows attackers to exploit a cross-site scripting vulnerability, which can compromise the security of web-based management interfaces.
Is CVE-2015-2883 specific to any particular version of Philips products?
Yes, CVE-2015-2883 specifically affects the Philips In.Sight B120/37 model.
Can CVE-2015-2883 lead to unauthorized access to my device?
Yes, if exploited, CVE-2015-2883 can potentially allow unauthorized users to execute scripts in the context of the user's session.