Cross-Site Scripting Vulnerability in Control Center Server by Siemens
CVE-2019-19294
6.3MEDIUM
What is CVE-2019-19294?
A stored Cross-Site Scripting vulnerability has been found in the web interface of Control Center Server (CCS) software. All versions prior to V1.5.0 are affected. This vulnerability arises from inadequate input validation in multiple fields, allowing an authenticated attacker to inject malicious JavaScript code. The result is the potential execution of the injected code in the browser context of any user who accesses the compromised web content, thereby compromising user data and security.
Affected Version(s)
Control Center Server (CCS) All versions < V1.5.0