Cross-site Scripting Vulnerability in CONPROSYS HMI System by Contec
CVE-2023-22373

5.4MEDIUM

Key Information:

Vendor
CVE Published:
20 January 2023

What is CVE-2023-22373?

The CONPROSYS HMI System (CHS) is vulnerable to cross-site scripting, allowing remote authenticated attackers to inject arbitrary scripts. This vulnerability can lead to unauthorized access to sensitive information, posing significant risks to the security and integrity of the system.

Affected Version(s)

CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.