CVE-2023-25551: XSS
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters over HTTP.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25551?
The severity of CVE-2023-25551 is medium with a severity value of 6.1.
What is the vulnerability type of CVE-2023-25551?
CVE-2023-25551 is a CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability.
Which products are affected by CVE-2023-25551?
StruxureWare Data Center Expert (V7.9.2 and prior) is affected by CVE-2023-25551.
How can I fix CVE-2023-25551?
To fix CVE-2023-25551, it is recommended to apply the necessary security patches provided by Schneider-electric.
Where can I find more information about CVE-2023-25551?
More information about CVE-2023-25551 can be found in the security and safety notice document provided by Schneider-electric: [Link](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-045-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-045-02.pdf).