Cross-Site Scripting Vulnerability in Microchip TimePictra
CVE-2026-3010
9.3CRITICAL
What is CVE-2026-3010?
An issue has been identified in Microchip TimePictra, where improper handling of input during web page generation may lead to a Cross-Site Scripting (XSS) vulnerability. This allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising the confidentiality and integrity of sensitive data. The vulnerability affects multiple versions of TimePictra, specifically from 11.0 through 11.3 SP2. Users are advised to apply the recommended security patches to mitigate this threat. For detailed information and reporting potential vulnerabilities, visit Microchip's official advisory page.
Affected Version(s)
TimePictra 11.0 <= 11.3 SP2
