First published: Mon Apr 10 2017(Updated: )
Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to deviceSettings.php or shareDevice.php.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Philips In.sight B120\37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2883 is classified as a medium severity vulnerability due to its potential impact on the confidentiality of user data.
To fix CVE-2015-2883, update the Philips In.Sight B120/37 firmware to the latest version provided by Philips that addresses this XSS vulnerability.
CVE-2015-2883 allows attackers to exploit a cross-site scripting vulnerability, which can compromise the security of web-based management interfaces.
Yes, CVE-2015-2883 specifically affects the Philips In.Sight B120/37 model.
Yes, if exploited, CVE-2015-2883 can potentially allow unauthorized users to execute scripts in the context of the user's session.