Stored Cross-Site Scripting Flaw in SIMATIC PCS neo by Siemens
CVE-2023-46099
4.8MEDIUM
What is CVE-2023-46099?
A stored cross-site scripting vulnerability has been discovered in the Administration Console of SIMATIC PCS neo. This security flaw affects all versions prior to V4.1 and allows an attacker with elevated privileges to inject malicious JavaScript code into the application. The injected code can then be executed by another user, potentially compromising sensitive information and endangering system integrity.
Affected Version(s)
SIMATIC PCS neo All versions < V4.1