PT-2022-11423 · Unknown · Climatix Pol909
Published
2022-03-08
·
Updated
2022-03-11
·
CVE-2021-41541
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Climatix POL909 (AWB module) versions prior to V11.44
Climatix POL909 (AWM module) versions prior to V11.36
Description
A cross-site scripting (XSS) issue has been identified in the Group Management page of affected devices. This issue allows an attacker to send malicious JavaScript code, potentially resulting in the hijacking of user cookie or session tokens, redirection to a malicious webpage, and unintended browser actions.
Recommendations
For Climatix POL909 (AWB module) versions prior to V11.44, update to version V11.44 or later to resolve the issue.
For Climatix POL909 (AWM module) versions prior to V11.36, update to version V11.36 or later to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Climatix Pol909