CVE-2018-7504: XSS
A Protection Mechanism Failure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The X-XSS-Protection response header is not set to block, allowing attempts at reflected cross-site scripting.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Set the X-XSS-Protection response header to block to prevent reflected cross-site scripting attempts.
OSIsoft PI Vision X-XSS-Protection response header = block
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-7504.
What is the title of this vulnerability?
The title of this vulnerability is 'A Protection Mechanism Failure issue was discovered in OSIsoft PI Vision versions 2017 and prior.'
What is the severity of CVE-2018-7504?
The severity of CVE-2018-7504 is medium with a CVSS score of 6.1.
What is the affected software?
The affected software is OSIsoft PI Vision versions 2017 and prior.
How does this vulnerability manifest?
This vulnerability allows attempts at reflected cross-site scripting due to the X-XSS-Protection response header not being set to block.