Cross-Site Scripting Vulnerability in StruxureWare Data Center Expert from Schneider Electric
CVE-2023-25551
6.1MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 18 April 2023
What is CVE-2023-25551?
A Cross-Site Scripting vulnerability has been identified in the StruxureWare Data Center Expert, specifically on the DCE file upload endpoint. The vulnerability arises due to improper neutralization of user input parameters during web page generation, allowing for potential manipulation of the application by an attacker. By exploiting this flaw, attackers could execute arbitrary scripts in the context of the user’s session, which may lead to unauthorized access or data exposure.
Affected Version(s)
StruxureWare Data Center Expert All