Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xm3f-qg9m-jmh5

Опубликовано: 12 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.5

Описание

A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local access to the connector admin portal to persist arbitrary JavaScript code that will be executed by other users who visit affected pages.

A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local access to the connector admin portal to persist arbitrary JavaScript code that will be executed by other users who visit affected pages.

EPSS

Процентиль: 3%
0.00016
Низкий

6.9 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.5
nvd
8 месяцев назад

A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local access to the connector admin portal to persist arbitrary JavaScript code that will be executed by other users who visit affected pages.

CVSS3: 5.5
fstec
8 месяцев назад

Уязвимость программного обеспечения для интеграции данных PI Connector for CygNet, связанная с недостаточной защитой структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 3%
0.00016
Низкий

6.9 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-79