CVE-2023-5987

Description

A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

CVEListV5schneider_electric/ecostruxure_power_monitoring_expert_(pme)Version 2020 CU2 and prior, Version 2021 CU1 and prior+1
CVEListV5schneider_electric/ecostruxure_power_operation_(epo)_–_advanced_reporting_and_dashboards_moduleAdvanced Reporting and Dashboards Module 2020 prior to CU3, Advanced Reporting and Dashboards Module 2021 prior to CU2 for EcoStruxure Power Operation 2021+1

Patches

🔴Vulnerability Details

2
CVEList
CVE-2023-5987: A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to2023-11-15
GHSA
GHSA-f85w-wprq-6vjg: A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to2023-11-15
CVE-2023-5987 (MEDIUM CVSS 6.1) | A CWE-79 Improper Neutralization of | cvebase.io