CVE-2014-5397: Schneider Electric Wonderware Cross-site Scripting
Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5397?
CVE-2014-5397 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-5397?
To mitigate CVE-2014-5397, it is recommended to apply the latest patches provided by Schneider Electric for affected versions.
What systems are affected by CVE-2014-5397?
CVE-2014-5397 affects Schneider Electric Wonderware Information Server Portal versions 4.0 SP1 through 5.5.
What type of attack can CVE-2014-5397 facilitate?
CVE-2014-5397 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
What are the consequences of exploiting CVE-2014-5397?
Exploiting CVE-2014-5397 could lead to unauthorized access to user information and manipulation of the web application.