PT-2021-18390 · Softing Ag · Opc Toolbox

Gianni Palombizio

+3

·

Published

2021-04-02

·

Updated

2021-04-08

·

CVE-2021-29661

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Softing AG OPC Toolbox versions prior to 4.10.1.13036
Description The issue allows for Stored XSS via the ITEMLISTVALUES##ITEMID parameter in the "/en/diag values.html" API endpoint, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it.
Recommendations For versions prior to 4.10.1.13036, as a temporary workaround, consider restricting access to the "/en/diag values.html" API endpoint to minimize the risk of exploitation. Avoid using the ITEMLISTVALUES##ITEMID parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29661

Affected Products

Opc Toolbox