Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Gianni Palombizio

#18897of 53,635
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-18389
8.8
2021-04-02
Softing Ag · Opc Toolbox · CVE-2021-29660
**Name of the Vulnerable Software and Affected Versions** Softing AG OPC Toolbox versions prior to 4.10.1.13036 **Description** A Cross-Site Request Forgery issue allows attackers to reset the administrative password by inducing the Administrator user to browse a URL controlled by an attacker. **Recommendations** For versions prior to 4.10.1.13036, update to a version that contains a fix for this issue.
PT-2021-18390
5.4
2021-04-02
Softing Ag · Opc Toolbox · CVE-2021-29661
**Name of the Vulnerable Software and Affected Versions** Softing AG OPC Toolbox versions prior to 4.10.1.13036 **Description** The issue allows for Stored XSS via the `ITEMLISTVALUES##ITEMID` parameter in the "/en/diag values.html" API endpoint, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it. **Recommendations** For versions prior to 4.10.1.13036, as a temporary workaround, consider restricting access to the "/en/diag values.html" API endpoint to minimize the risk of exploitation. Avoid using the `ITEMLISTVALUES##ITEMID` parameter in the affected API endpoint until the issue is resolved.