Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2.
The vulnerability consists of improper filtering and encoding of input data before embedding it in generated HTML pages of the TimePictra application. An attacker can inject malicious script code (e.g., JavaScript) that will be executed in the victim's browser. The attack does not require authentication or user interaction on the attacker's side, and the vector is the network (AV:N), which means it can be carried out remotely. The vulnerability type indicates the possibility of querying the system for information using specially crafted queries.
An attacker can gain access to sensitive information in the context of the victim's browser (e.g., session cookies, authentication tokens) and perform unauthorized operations on behalf of the logged-in user, as well as potentially read or modify data presented by the application.
Apply patches available from the manufacturer in accordance with the references. Information about updates is available at: https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timepictra-stored-cross-site-scripting
Microchip TimePictra versions 11.0 to 11.3 SP2 (inclusive).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMicrochip Timepictra
APPMicrochip11.311.0 – 11.3
Related vulnerabilities
Brak uwierzytelnienia dla funkcji krytycznych w Microchip TimePictra
RCE przez buffer overflow w serwerze DHCP Microchip Advanced Software Framework
Nieautoryzowany dostęp w maxView Storage Manager via Redfish Server
Nieautoryzowany dostęp w Microchip maxView Storage Manager przez serwer Redfish
Microchip MPLAB Net — słaba losowość numerów sekwencyjnych TCP (ISN)