First published: Thu Oct 27 2022(Updated: )
An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Videojet Multi 4000 Firmware | <=6.31.0010 | |
Bosch Videojet Multi 4000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-40183.
The severity of CVE-2022-40183 is medium with a CVSS score of 4.7.
The affected software for CVE-2022-40183 is Bosch Videojet Multi 4000 Firmware versions up to 6.31.0010.
CVE-2022-40183 exploits an error in the URL handler of the VIDEOJET multi 4000, allowing an attacker with knowledge of the encoder address to send a crafted link to a user, which will execute JavaScript code in the context of the user.
Please refer to the official Bosch security advisory at https://psirt.bosch.com/security-advisories/bosch-sa-454166-bt.html for information on available fixes.