First published: Fri Jan 28 2022(Updated: )
HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView, thus allowing the Application to display web resources controlled by the attacker.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
<3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this HTML code injection vulnerability in Android Application Bosch Video Security is CVE-2021-23863.
The severity of CVE-2021-23863 is medium with a CVSS score of 6.1.
The affected software for CVE-2021-23863 is Bosch Video Security version 3.2.3 or earlier on Android.
An attacker can exploit CVE-2021-23863 by injecting random HTML code into a component loaded by WebView in the Bosch Video Security application.
Yes, you can find references for CVE-2021-23863 at the following links: [Bosch SA-844050-BT](https://psirt.bosch.com/security-advisories/bosch-sa-844050-bt.html) and [Bosch SA-844050](https://psirt.bosch.com/security-advisories/bosch-sa-844050.html).