CVE-2023-3971: Controller: html injection in custom login info
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this HTML injection flaw?
The vulnerability ID of this HTML injection flaw is CVE-2023-3971.
What is the severity of CVE-2023-3971?
The severity of CVE-2023-3971 is high.
How does the HTML injection flaw in Controller in the user interface settings work?
The HTML injection flaw allows an attacker to inject HTML in the user interface settings, creating a custom login page to capture credentials and potentially leading to a complete compromise.
Which versions of Automation Controller are affected by CVE-2023-3971?
Automation Controller versions up to and excluding 4.3.11 and 4.4.1 are affected by CVE-2023-3971.
How can I fix the HTML injection flaw in Controller in the user interface settings?
To fix the HTML injection flaw, update Automation Controller to version 4.3.11 or higher and 4.4.1 or higher, depending on the affected version.