PT-2021-23442 · Socomec · Socomec Remote View Pro
Published
2021-12-15
·
Updated
2021-12-17
·
CVE-2021-41871
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Socomec REMOTE VIEW PRO version 2.0.41.4
Description
An issue was discovered where improper validation of input into the
username field allows for a stored XSS payload. This payload is executed when an administrator views the System Event Log.Recommendations
For Socomec REMOTE VIEW PRO version 2.0.41.4, consider disabling the
username field input validation temporarily until a patch is available to prevent potential XSS attacks. Restrict access to the System Event Log to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Socomec Remote View Pro