CVE-2023-5987
Severity
6.1MEDIUM
EPSS
0.1%
top 68.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 15
Description
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
vulnerability that could cause a vulnerability leading to a cross site scripting condition where
attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing
the injected payload.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages4 packages
▶CVEListV5schneider_electric/ecostruxure_power_monitoring_expert_(pme)Version 2020 CU2 and prior, Version 2021 CU1 and prior+1
▶CVEListV5schneider_electric/ecostruxure_power_operation_(epo)_–_advanced_reporting_and_dashboards_moduleAdvanced Reporting and Dashboards Module 2020 prior to CU3, Advanced Reporting and Dashboards Module 2021 prior to CU2 for EcoStruxure Power Operation 2021+1
▶CVEListV5schneider_electric/ecostruxure_power_scada_operation_(pso)_-_advanced_reporting_and_dashboards_moduleEcoStruxure Power SCADA Operation (PSO) 2020 or 2020 R2
Patches
🔴Vulnerability Details
2CVEList▶
CVE-2023-5987: A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
vulnerability that could cause a vulnerability leading to↗2023-11-15
GHSA▶
GHSA-f85w-wprq-6vjg: A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
vulnerability that could cause a vulnerability leading to↗2023-11-15