PT-2022-11424 · Unknown · Climatix Pol909

Published

2022-03-08

·

Updated

2022-03-11

·

CVE-2021-41542

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Climatix POL909 (AWB module) versions prior to V11.44 Climatix POL909 (AWM module) versions prior to V11.36
Description A security issue has been identified in the User Management page of affected devices, making it vulnerable to cross-site scripting (XSS). This allows an attacker to send malicious JavaScript code, potentially resulting in the hijacking of the user's cookie or session tokens, redirecting the user to a malicious webpage, and performing unintended browser actions.
Recommendations For Climatix POL909 (AWB module) versions prior to V11.44, update to version V11.44 or later. For Climatix POL909 (AWM module) versions prior to V11.36, update to version V11.36 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41542

Affected Products

Climatix Pol909