First published: Wed Dec 07 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
APC PowerChute Network Shutdown | =6.0 | |
APC PowerChute Network Shutdown | =7.1 | |
APC PowerChute Network Shutdown | =7.0.4 | |
APC PowerChute Network Shutdown | <=8.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4263 is rated as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2011-4263, update to Schneider Electric PowerChute Business Edition version 8.5 or later.
CVE-2011-4263 affects Schneider Electric PowerChute Business Editions prior to version 8.5, including versions 6.0, 7.0.4, and 7.1.
CVE-2011-4263 can be exploited for cross-site scripting (XSS), allowing attackers to inject scripts into web pages viewed by users.
No, updating to version 8.5 or later of Schneider Electric PowerChute Business Edition mitigates the risk associated with CVE-2011-4263.