First published: Fri Jan 20 2023(Updated: )
Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and obtain the sensitive information.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Contec CONPROSYS HMI System | <=3.4.5 | |
Contec CONPROSYS HMI System (CHS): Ver.3.4.4 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-22373.
The severity of CVE-2023-22373 is medium (5.4).
CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier is affected by CVE-2023-22373.
CVE-2023-22373 allows a remote authenticated attacker to inject an arbitrary script and obtain sensitive information.
Update CONPROSYS HMI System to a version later than 3.4.5 to fix CVE-2023-22373.