CVE-2022-40183

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
27/10/2022
Last modified:
31/10/2022

Description

An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:bosch:videojet_multi_4000_firmware:*:*:*:*:*:*:*:* 6.31.0010 (including)
cpe:2.3:h:bosch:videojet_multi_4000:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools