Cross-Site Scripting Vulnerability in CONPROSYS HMI System by Contec
CVE-2023-28651

4.8MEDIUM

Key Information:

Vendor
CVE Published:
1 June 2023

What is CVE-2023-28651?

A cross-site scripting vulnerability exists in the CONPROSYS HMI System (CHS) that may allow attackers to execute arbitrary scripts on a user's web browser. This issue arises when an administrator applies specially crafted configurations while logged into the system. Consequently, any other user accessing the affected product with administrative privileges could be affected by the malicious script, leading to potential unauthorized actions or data exposure.

Affected Version(s)

CONPROSYS HMI System (CHS) versions prior to 3.5.3

References

EPSS Score

13% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.