Stored XSS Vulnerability in Socomec REMOTE VIEW PRO by Socomec
CVE-2021-41871

5.4MEDIUM

Key Information:

Vendor

Socomec

Vendor
CVE Published:
15 December 2021

What is CVE-2021-41871?

A vulnerability exists in Socomec's REMOTE VIEW PRO 2.0.41.4 that allows for stored XSS attacks due to improper validation of the input in the username field. This flaw can be exploited when an administrator views the System Event Log, leading to the execution of malicious scripts. Organizations must address this vulnerability to enhance their cybersecurity posture and protect sensitive information.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.