Description
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- Schneider Electric / EcoStruxure™ Power Monitoring Expert (PME)Version 2020 CU2 and prior – Version 2020 CU2 and prior
- Schneider Electric / EcoStruxure™ Power Monitoring Expert (PME)Version 2021 CU1 and prior – Version 2021 CU1 and prior
- Schneider Electric / EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards ModuleAdvanced Reporting and Dashboards Module 2021 prior to CU2 for EcoStruxure Power Operation 2021 – Advanced Reporting and Dashboards Module 2021 prior to CU2 for EcoStruxure Power Operation 2021
- Schneider Electric / EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards ModuleAdvanced Reporting and Dashboards Module 2020 prior to CU3 – Advanced Reporting and Dashboards Module 2020 prior to CU3
- Schneider Electric / EcoStruxure Power SCADA Operation (PSO) - Advanced Reporting and Dashboards ModuleEcoStruxure Power SCADA Operation (PSO) 2020 or 2020 R2 – EcoStruxure Power SCADA Operation (PSO) 2020 or 2020 R2