First published: Wed Nov 15 2023(Updated: )
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure Power Monitoring Expert | =2020 | |
Schneider Electric EcoStruxure Power Monitoring Expert | =2020-cumulative_update_1 | |
Schneider Electric EcoStruxure Power Monitoring Expert | =2020-cumulative_update_2 | |
Schneider Electric EcoStruxure Power Monitoring Expert | =2021 | |
Schneider Electric EcoStruxure Power Monitoring Expert | =2021-cumulative_update_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-5987.
The severity of CVE-2023-5987 is medium (6.1).
The CWE ID for this vulnerability is CWE-79.
CVE-2023-5987 affects Schneider-electric Ecostruxure Power Monitoring Expert (2020) and its cumulative updates (2020-cumulative_update_1 and 2020-cumulative_update_2).
To fix CVE-2023-5987, it is recommended to apply the security update provided by Schneider Electric.