CVE-2023-48248: XSS
The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48248?
CVE-2023-48248 has been classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2023-48248?
To remediate CVE-2023-48248, ensure that you update the affected Bosch Nexo operating system to the latest patched version.
Who is affected by CVE-2023-48248?
CVE-2023-48248 affects authenticated users of the Bosch Nexo operating system versions between 1000 and 1500-sp2.
What attack vector is involved in CVE-2023-48248?
CVE-2023-48248 can be exploited via crafted URLs or HTTP requests to upload and execute malicious files.
What are the potential impacts of CVE-2023-48248?
The exploitation of CVE-2023-48248 allows attackers to execute arbitrary client-side scripts within a victim’s session.