CVE-2024-10208: Cross Site Scripting vulnerability in APROL Web Portal
Published Mar 25, 2025
·Updated
An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to insert malicious code which is then executed in the context of the user’s browser session.
Affected Software
1 affected component
B&R APROL<4.4-00P5
Event History
Mar 25, 2025
CVE Published
via MITRE·04:43 AM
Data Sourced
via MITRE·04:43 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10208?
CVE-2024-10208 is considered a high severity vulnerability due to the potential for code injection attacks.
2
How do I fix CVE-2024-10208?
To fix CVE-2024-10208, B&R APROL users should upgrade to version 4.4-00P5 or later.
3
Who is affected by CVE-2024-10208?
CVE-2024-10208 affects users of B&R APROL versions prior to 4.4-00P5.
4
What type of attack can CVE-2024-10208 facilitate?
CVE-2024-10208 can enable authenticated network-based attackers to execute malicious code in a user's browser session.
5
Is user authentication required for CVE-2024-10208 exploitation?
Yes, CVE-2024-10208 requires that the attacker is authenticated to exploit the vulnerability.