Eaton IPM Vulnerable to Stored Cross-Site Scripting
CVE-2021-23282
5.2MEDIUM
What is CVE-2021-23282?
Eaton Intelligent Power Manager versions prior to 1.70 are impacted by a vulnerability that allows stored cross site scripting. This vulnerability arises from inadequate validation of inputs from certain resources within the IPM software. An attacker would require local network access and administrator interaction to exploit this flaw, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
Intelligent Power Manager (IPM) 0 < 1.70