CVE-2021-22676: XSS
UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and unintended browser action on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22676?
CVE-2021-22676 has a medium severity rating due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2021-22676?
To remediate CVE-2021-22676, update your Advantech WebAccess/SCADA to version 8.4.5 or later, or version 9.0.1 or later.
What are the consequences of exploiting CVE-2021-22676?
Exploitation of CVE-2021-22676 can lead to cookie/session token hijacking, redirection to malicious sites, and unintended actions in the browser.
Which versions of WebAccess/SCADA are affected by CVE-2021-22676?
CVE-2021-22676 affects Advantech WebAccess/SCADA versions prior to 8.4.5 and between 9.0.0 and 9.0.1.
Where can I find more information about CVE-2021-22676?
Further details about CVE-2021-22676 can be found in security advisories from cybersecurity agencies.