Cross-Site Scripting Vulnerability in APC Network Management Cards
CVE-2021-22810
6.1MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 28 January 2022
What is CVE-2021-22810?
A Cross-Site Scripting vulnerability exists in Schneider Electric's APC Network Management Cards that could allow an attacker to execute arbitrary scripts via a malicious URL. Specifically, this flaw can be exploited if a privileged user accesses a specially crafted URL targeting a delete policy file. The vulnerability affects various models of 1-Phase and 3-Phase UPS systems, Power Distribution Units, and environmental monitoring units, particularly those running outdated versions of the NMC firmware. This threat can lead to unauthorized actions and data exposure if not mitigated promptly.