PT-2021-11076 · Pnpscada · Pnpscada
Published
2021-02-10
·
Updated
2021-02-13
·
CVE-2020-24842
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
PNPSCADA version 2.200816204020
Description:
The issue allows cross-site scripting (XSS), which can execute arbitrary JavaScript in the victim's browser. This means an attacker could potentially inject malicious scripts into a website, allowing them to steal user data or take control of the user's session.
Recommendations:
For PNPSCADA version 2.200816204020, as a temporary workaround, consider implementing input validation and sanitization to prevent malicious JavaScript code from being injected into the application. Restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pnpscada