Cross-Site Scripting Vulnerability in CONPROSYS HMI System by Contec
CVE-2023-28651
4.8MEDIUM
What is CVE-2023-28651?
A cross-site scripting vulnerability exists in the CONPROSYS HMI System (CHS) that may allow attackers to execute arbitrary scripts on a user's web browser. This issue arises when an administrator applies specially crafted configurations while logged into the system. Consequently, any other user accessing the affected product with administrative privileges could be affected by the malicious script, leading to potential unauthorized actions or data exposure.
Affected Version(s)
CONPROSYS HMI System (CHS) versions prior to 3.5.3
References
EPSS Score
13% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved