HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView, thus allowing the Application to display web resources controlled by the attacker.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://psirt.bosch.com/security-advisories/bosch-sa-844050.html | broken link |
https://psirt.bosch.com/security-advisories/bosch-sa-844050-bt.html | vendor advisory |