First published: Wed Jan 15 2020(Updated: )
OSIsoft PI Vision, PI Vision 2017 R2 and PI Vision 2017 R2 SP1. The affected product is vulnerable to cross-site scripting, which may allow invalid input to be introduced.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
OSIsoft PI Vision | =2017-r2 | |
OSIsoft PI Vision | =2017-r2_sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18273 has been classified as a medium severity vulnerability due to its cross-site scripting risk.
To remediate CVE-2019-18273, upgrade to the latest version of OSIsoft PI Vision that addresses the cross-site scripting vulnerability.
CVE-2019-18273 affects OSIsoft PI Vision 2017 R2 and PI Vision 2017 R2 SP1.
CVE-2019-18273 is a cross-site scripting (XSS) vulnerability that allows the introduction of invalid input.
Yes, CVE-2019-18273 can be exploited remotely by an attacker to inject malicious scripts.