PT-2021-11076 · Pnpscada · Pnpscada

Published

2021-02-10

·

Updated

2021-02-13

·

CVE-2020-24842

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: PNPSCADA version 2.200816204020
Description: The issue allows cross-site scripting (XSS), which can execute arbitrary JavaScript in the victim's browser. This means an attacker could potentially inject malicious scripts into a website, allowing them to steal user data or take control of the user's session.
Recommendations: For PNPSCADA version 2.200816204020, as a temporary workaround, consider implementing input validation and sanitization to prevent malicious JavaScript code from being injected into the application. Restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24842

Affected Products

Pnpscada