CVE-2021-27436: XSS
WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser actions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27436?
CVE-2021-27436 has a medium severity rating due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2021-27436?
To mitigate CVE-2021-27436, upgrade to WebAccess/SCADA version 9.1 or later, which includes patches for this vulnerability.
Which versions of WebAccess/SCADA are affected by CVE-2021-27436?
CVE-2021-27436 affects WebAccess/SCADA versions 9.0 and prior.
What types of attacks can be executed through CVE-2021-27436?
CVE-2021-27436 allows attackers to execute cross-site scripting attacks that can hijack user sessions or redirect users to malicious sites.
Who is the vendor responsible for CVE-2021-27436?
The vendor responsible for CVE-2021-27436 is Advantech.