Cross-Site Scripting Vulnerability in Andover Continuum by Schneider Electric
CVE-2020-7481

6.1MEDIUM

Key Information:

Vendor
CVE Published:
23 March 2020

Summary

A Cross-Site Scripting vulnerability exists within Andover Continuum, allowing attackers to inject malicious scripts into webpages. This can lead to unauthorized actions on behalf of users or the exposure of sensitive data. It is essential for users to implement security measures to mitigate potential exploitation when operating the product's web server.

Affected Version(s)

Andover Continuum (All ) Andover Continuum (All versions)

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.