Softing Ag · Opc Toolbox · CVE-2021-29661
**Name of the Vulnerable Software and Affected Versions**
Softing AG OPC Toolbox versions prior to 4.10.1.13036
**Description**
The issue allows for Stored XSS via the `ITEMLISTVALUES##ITEMID` parameter in the "/en/diag values.html" API endpoint, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it.
**Recommendations**
For versions prior to 4.10.1.13036, as a temporary workaround, consider restricting access to the "/en/diag values.html" API endpoint to minimize the risk of exploitation. Avoid using the `ITEMLISTVALUES##ITEMID` parameter in the affected API endpoint until the issue is resolved.