Cross-Site Scripting Vulnerability in CONPROSYS HMI System by Contec
CVE-2023-28651
What is CVE-2023-28651?
A cross-site scripting vulnerability exists in the CONPROSYS HMI System (CHS) that may allow attackers to execute arbitrary scripts on a user's web browser. This issue arises when an administrator applies specially crafted configurations while logged into the system. Consequently, any other user accessing the affected product with administrative privileges could be affected by the malicious script, leading to potential unauthorized actions or data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CONPROSYS HMI System (CHS) versions prior to 3.5.3
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
