A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NBr Automation Automation Runtime
APPBr-Automation< i4.93
Powiązane podatności
B&R Automation Runtime: serwer FTP obsługuje przestarzałe protokoły szyfrowania
Słabe uwierzytelnianie SNMP w B&R Automation Runtime umożliwia modyfikację konfiguracji
Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versi...
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4....
Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based atta...