PT-2024-18962 · Steve · Steve
Calum Hutton
+1
·
Published
2024-08-12
·
Updated
2024-08-13
·
CVE-2024-21550
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SteVe (affected versions not specified)
Description
SteVe is an open platform that implements different versions of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets, leading to persistent Cross-Site Scripting in the SteVe management interface.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Steve