First published: Wed Nov 15 2023(Updated: )
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Power Monitoring Expert | =2020 | |
Schneider-electric Ecostruxure Power Monitoring Expert | =2020-cumulative_update_1 | |
Schneider-electric Ecostruxure Power Monitoring Expert | =2020-cumulative_update_2 | |
Schneider-electric Ecostruxure Power Monitoring Expert | =2021 | |
Schneider-electric Ecostruxure Power Monitoring Expert | =2021-cumulative_update_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5986 is a URL Redirection to Untrusted Site vulnerability that could lead to a cross-site scripting attack.
CVE-2023-5986 has a severity rating of 8.2 (high).
Schneider-electric Ecostruxure Power Monitoring Expert 2020, 2020 Cumulative Update 1, 2020 Cumulative Update 2, 2021, and 2021 Cumulative Update 1 are affected by CVE-2023-5986.
Attackers can exploit CVE-2023-5986 by providing a URL-encoded input to cause the software's web application to redirect to an untrusted site, leading to a cross-site scripting attack.
To fix CVE-2023-5986, apply the necessary security updates provided by Schneider-electric.