First published: Wed Jul 06 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch BLADEcontrol-WebVIS | <=3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4508 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
To fix CVE-2016-4508, upgrade Bosch BLADEcontrol-WebVIS to version 3.0.3 or later.
CVE-2016-4508 allows remote attackers to perform cross-site scripting attacks, leading to arbitrary code execution in the user's browser.
CVE-2016-4508 affects versions of Bosch BLADEcontrol-WebVIS up to and including 3.0.2.
If you are using an affected version of Bosch BLADEcontrol-WebVIS that has not been updated, CVE-2016-4508 remains a significant risk.