CVE-2023-28651: XSS
Cross-site scripting vulnerability exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. If a user who can access the affected product with an administrative privilege configures specially crafted settings, an arbitrary script may be executed on the web browser of the other user who is accessing the affected product with an administrative privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28651?
CVE-2023-28651 has been classified with a high severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2023-28651?
To fix CVE-2023-28651, upgrade your CONPROSYS HMI System to version 3.5.3 or later.
Who is affected by CVE-2023-28651?
CVE-2023-28651 affects users of the CONPROSYS HMI System prior to version 3.5.3 who have administrative privileges.
What impact does CVE-2023-28651 have?
The impact of CVE-2023-28651 includes the potential execution of arbitrary scripts in the web browsers of other users.
Is there a workaround for CVE-2023-28651?
The primary mitigation for CVE-2023-28651 is to upgrade to the latest version, as no specific workaround is provided.