First published: Mon Aug 12 2024(Updated: )
SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Odoo Community | <=3.5.1 | |
Odoo Community | =3.6.0 | |
Odoo Community | =3.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21550 is classified as a high-severity vulnerability due to its potential for persistent Cross-Site Scripting attacks.
To mitigate CVE-2024-21550, upgrade your SteVe installation to version 3.7.0 or later.
CVE-2024-21550 affects SteVe versions up to 3.5.1, 3.6.0, and 3.7.0.
CVE-2024-21550 enables attackers to inject arbitrary HTML and JavaScript code via WebSockets.
SteVe is an open platform that implements different versions of the OCPP protocol for managing Electric Vehicle charge points.