CVE-2023-48248
10.01.2024, 11:15
The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victims session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned file.
Vendor | Product | Version |
---|---|---|
bosch | nexo-os | 1000 ≤ 𝑥 ≤ 1500-sp2 |
𝑥
= Vulnerable software versions