Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NCarel Pcoweb Card
HWCarelall versionsCarel Pcoweb Card Firmware
OSCarel< b1.2.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2022-37122HIGH7.5same product
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 ...
CVE-2019-11369HIGH8.8same product
An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores clea...
CVE-2019-9484HIGH7.5same product
The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attacker...
CVE-2022-34827CRITICAL9.9PL ✓same vendor
Nieprawidłowa kontrola dostępu w Carel Boss Mini 1.5.0
CVE-2019-13553CRITICAL9.8PL ✓same vendor
Hardcoded credentials w Rittal Chiller SK 3232 / Carel pCOWeb