CRITICAL🇵🇱 Wersja polska

CVE-2026-3010

CVSS 9.3v4.0pub. 2026-02-28upd. 2026-03-10

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2.

🤖 AI Analysis
How it works

The vulnerability consists of improper filtering and encoding of input data before embedding it in generated HTML pages of the TimePictra application. An attacker can inject malicious script code (e.g., JavaScript) that will be executed in the victim's browser. The attack does not require authentication or user interaction on the attacker's side, and the vector is the network (AV:N), which means it can be carried out remotely. The vulnerability type indicates the possibility of querying the system for information using specially crafted queries.

Impact

An attacker can gain access to sensitive information in the context of the victim's browser (e.g., session cookies, authentication tokens) and perform unauthorized operations on behalf of the logged-in user, as well as potentially read or modify data presented by the application.

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references. Information about updates is available at: https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timepictra-stored-cross-site-scripting

Who is affected

Microchip TimePictra versions 11.0 to 11.3 SP2 (inclusive).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Microchip Timepictra

    APP
    Microchip
    11.311.0 – 11.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-2844CRITICAL9.3PL ✓same product

Brak uwierzytelnienia dla funkcji krytycznych w Microchip TimePictra

CVE-2024-7490CRITICAL9.5PL ✓same vendor

RCE przez buffer overflow w serwerze DHCP Microchip Advanced Software Framework

CVE-2023-51438CRITICAL10.0PL ✓same vendor

Nieautoryzowany dostęp w maxView Storage Manager via Redfish Server

CVE-2024-22216CRITICAL10.0PL ✓same vendor

Nieautoryzowany dostęp w Microchip maxView Storage Manager przez serwer Redfish

CVE-2020-27636CRITICAL9.1PL ✓same vendor

Microchip MPLAB Net — słaba losowość numerów sekwencyjnych TCP (ISN)