CVE-2021-22723: XSS
A CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-siteScripting) through Cross-Site Request Forgery (CSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to impersonate the user who manages the charging station or carry out actions on their behalf when crafted malicious parameters are submitted to the charging station web server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22723?
The severity of CVE-2021-22723 is medium.
Which software versions are affected by CVE-2021-22723?
The affected software versions are EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and Evlink Smart Wallbox Evb1a (all versions prior to R8 V3.4.0.1).
What is the CWE ID of CVE-2021-22723?
The CWE ID of CVE-2021-22723 is CWE-79.
How can I fix CVE-2021-22723?
To fix CVE-2021-22723, it is recommended to update the affected software versions to R8 V3.4.0.1 or later.
Where can I find more information about CVE-2021-22723?
You can find more information about CVE-2021-22723 at the following link: [Schneider Electric Security Advisory SEVD-2021-194-06](http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06).