Reflected XSS Vulnerability in PTC ThingWorx Platform
CVE-2018-17218

5.4MEDIUM

Key Information:

Vendor

Ptc

Vendor
CVE Published:
1 October 2018

What is CVE-2018-17218?

A reflected cross-site scripting (XSS) vulnerability exists in the PTC ThingWorx Platform versions 6.5 through 8.2. This issue arises from insufficient validation of user-supplied input within the SQUEAL search function. Attackers can exploit this vulnerability to execute arbitrary scripts in the context of the user’s browser, potentially leading to unauthorized access or data manipulation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.