PT-2021-19474 · Automated Logic · Automated Logic Webctrl/Webctrl Oem
3Ndg4Me
·
Published
2021-10-22
·
Updated
2021-11-28
·
CVE-2021-31682
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Automated Logic WebCTRL/WebCTRL OEM versions 6.5 and below
Description
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains an issue that allows for reflected XSS attacks due to the
operatorlocale GET parameter not being sanitized. This occurs when a basic XSS payload is passed to the vulnerable operatorlocale parameter, which is then reflected in the output without proper sanitization.Recommendations
For versions 6.5 and below, consider disabling the
operatorlocale parameter in the login portal until a patch is available to prevent reflected XSS attacks. Restrict access to the login portal to minimize the risk of exploitation. Avoid using the operatorlocale parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Automated Logic Webctrl/Webctrl Oem