CVE-2020-12021: XSS
In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remotely execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12021?
CVE-2020-12021 is a vulnerability in OSIsoft PI Web API 2019 Patch 1 and previous versions that allows for a cross-site scripting attack.
How severe is the CVE-2020-12021 vulnerability?
The CVE-2020-12021 vulnerability has a severity level of critical.
What software versions are affected by CVE-2020-12021?
OSIsoft PI Web API versions up to and including 2019 Patch 1 (1.12.0.6346) are affected by CVE-2020-12021.
How can an attacker exploit CVE-2020-12021?
An attacker can exploit CVE-2020-12021 by executing arbitrary code through a cross-site scripting attack.
Is there a fix available for CVE-2020-12021?
It is recommended to upgrade to a version of OSIsoft PI Web API that is not affected by CVE-2020-12021. Refer to the vendor's website for the latest patches and updates.