Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-40183

Опубликовано: 27 окт. 2022
Источник: nvd
CVSS3: 5.8
CVSS3: 4.7
EPSS Низкий

Описание

An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:bosch:videojet_multi_4000_firmware:*:*:*:*:*:*:*:*
Версия до 6.31.0010 (включая)
cpe:2.3:h:bosch:videojet_multi_4000:-:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00542
Низкий

5.8 Medium

CVSS3

4.7 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 4.7
github
больше 3 лет назад

An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user.

EPSS

Процентиль: 67%
0.00542
Низкий

5.8 Medium

CVSS3

4.7 Medium

CVSS3

Дефекты

CWE-79
CWE-79