CVE-2021-23863
Last modified
CVE-2021-23863 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView, thus allowing the Application to display web resources controlled by the attacker.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView, thus allowing the Application to display web resources controlled by the attacker.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bosch | Video Security | < 3.2.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-23863?
How severe is CVE-2021-23863?
How do I fix CVE-2021-23863?
Are you affected by CVE-2021-23863?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
