CVE-2021-23863 Information

Description

HTML code injection vulnerability in Android Application Bosch Video Security version 3.2.3. or earlier when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView thus allowing the Application to display web resources controlled by the attacker.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://psirt.bosch.com/security-advisories/bosch-sa-844050.html https://psirt.bosch.com/security-advisories/bosch-sa-844050-bt.html

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: