First published: Fri Dec 02 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Vijeo Historian | =4.20 | |
Schneider-electric Vijeo Historian | =4.0 | |
Schneider-electric Vijeo Historian | =4.10 | |
Schneider-electric Vijeo Historian | <=4.30 | |
Schneider-electric Citecthistorian | <=4.30 | |
Schneider-electric Citecthistorian | =4.20 | |
Schneider-electric Citectscada Reports | <=4.10 | |
Schneider-electric Citectscada Reports | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4035 is categorized as a cross-site scripting (XSS) vulnerability, which can lead to significant security risks if exploited.
To fix CVE-2011-4035, users should upgrade to the latest versions of Schneider Electric Vijeo Historian, CitectHistorian, or CitectSCADA Reports as specified by the vendor.
CVE-2011-4035 affects Schneider Electric Vijeo Historian, CitectHistorian, and CitectSCADA Reports versions up to and including 4.30 and 4.10 respectively.
Organizations using affected versions of Schneider Electric software may be at risk of remote code execution due to CVE-2011-4035.
Attackers can leverage CVE-2011-4035 to inject arbitrary web scripts or HTML, potentially compromising user data or system integrity.