Cross-Site Scripting Vulnerability in Andover Continuum by Schneider Electric
CVE-2020-7482
6.1MEDIUM
Summary
A Cross-site Scripting (XSS) vulnerability has been identified in Andover Continuum, affecting all versions. This flaw can be exploited through the product's web server, allowing attackers to inject malicious scripts into web pages viewed by users. This may lead to unauthorized access to sensitive information and compromise user sessions. It is essential for users to update their systems and implement appropriate security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Andover Continuum (All ) Andover Continuum (All versions)
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved