PT-2026-22467 · Microchip · Timepictra
Bastion Security
+1
·
Published
2026-02-28
·
Updated
2026-03-10
·
CVE-2026-3010
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Microchip TimePictra versions 11.0 through 11.3 SP2
Description
The software contains an Improper Neutralization of Input During Web Page Generation issue, also known as Cross-site Scripting (XSS). This allows for a Query System for Information. The issue affects the software’s ability to properly handle user-supplied data when generating web pages, potentially leading to the execution of malicious scripts.
Recommendations
Versions 11.0 through 11.3 SP2 are affected and should be updated when a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Timepictra