Cross-site Scripting Vulnerability in APC and Schneider Electric Products
CVE-2021-22814
6.1MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 28 January 2022
What is CVE-2021-22814?
A cross-site scripting vulnerability exists in specific versions of Network Management Cards (NMC2) by Schneider Electric. This flaw allows an attacker to execute arbitrary scripts in the context of a user's session when malicious files are read and displayed. This vulnerability affects a wide range of products, including various uninterruptible power supplies (UPS), rack power distribution units, and environmental monitoring equipment, making it essential for users to apply recommended security patches and updates.