PT-2017-6619 · Philips · Philips In.Sight B120/37

Publicado

2017-04-10

·

Atualizado

2017-04-14

·

CVE-2015-2883

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Philips In.Sight B120/37
Description The issue is related to the Weaved cloud web service and involves XSS. This can be demonstrated by the name parameter to "deviceSettings.php" or "shareDevice.php" endpoints.
Recommendations For Philips In.Sight B120/37, avoid using the name parameter in the affected "deviceSettings.php" or "shareDevice.php" endpoints until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-2883

Produtos afetados

Philips In.Sight B120/37