A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). There is a stored cross-site scripting vulnerability in the Administration Console of the affected product, that could allow an attacker with high privileges to inject Javascript code into the application that is later executed by another legitimate user.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: siemens
Published: 2023-11-14T11:04:21.326Z
Updated: 2025-01-08T16:21:04.932Z
Reserved: 2023-10-16T11:24:12.686Z
Link: CVE-2023-46099

Updated: 2024-08-02T20:37:39.392Z

Status : Modified
Published: 2023-11-14T11:15:14.840
Modified: 2024-11-21T08:27:53.853
Link: CVE-2023-46099

No data.