PT-2021-19474 · Automated Logic · Automated Logic Webctrl/Webctrl Oem

3Ndg4Me

·

Published

2021-10-22

·

Updated

2021-11-28

·

CVE-2021-31682

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Automated Logic WebCTRL/WebCTRL OEM versions 6.5 and below
Description The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains an issue that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This occurs when a basic XSS payload is passed to the vulnerable operatorlocale parameter, which is then reflected in the output without proper sanitization.
Recommendations For versions 6.5 and below, consider disabling the operatorlocale parameter in the login portal until a patch is available to prevent reflected XSS attacks. Restrict access to the login portal to minimize the risk of exploitation. Avoid using the operatorlocale parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31682

Affected Products

Automated Logic Webctrl/Webctrl Oem