CVE-2021-3351: XSS
Published Aug 2, 2021
·Updated
OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.
Affected Software
1 affected component
Openplcproject Openplc<=2016-03-14
Event History
Aug 2, 2021
CVE Published
via MITRE·05:22 AM
Data Sourced
via MITRE·05:22 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for OpenPLC runtime?
The vulnerability ID for OpenPLC runtime is CVE-2021-3351.
2
What is the title of the vulnerability for OpenPLC runtime?
The title of the vulnerability for OpenPLC runtime is 'OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.'
3
What is the severity level of CVE-2021-3351?
CVE-2021-3351 has a severity level of medium.
4
How does the vulnerability in OpenPLC runtime occur?
The vulnerability in OpenPLC runtime occurs through stored XSS via the Device Name to the web server's Add New Device page.
5
How can I fix the vulnerability in OpenPLC runtime?
To fix the vulnerability in OpenPLC runtime, it is recommended to update to a version beyond 2016-03-14.