Stored XSS Vulnerability in Softing AG OPC Toolbox
CVE-2021-29661

5.4MEDIUM

Key Information:

Vendor

Softing

Vendor
CVE Published:
2 April 2021

What is CVE-2021-29661?

The OPC Toolbox by Softing AG, prior to version 4.10.1.13035, is susceptible to a stored XSS vulnerability through the parameter ITEMLISTVALUES##ITEMID. An attacker can exploit this flaw to inject malicious JavaScript payloads. When an authenticated user accesses the affected page, the injected payload is executed, potentially compromising user data and session integrity. This vulnerability underscores the importance of secure coding practices to validate and sanitize user input.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.