CVE-2024-21550: XSS
SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21550?
CVE-2024-21550 is classified as a high-severity vulnerability due to its potential for persistent Cross-Site Scripting attacks.
How do I fix CVE-2024-21550?
To mitigate CVE-2024-21550, upgrade your SteVe installation to version 3.7.0 or later.
What types of systems are affected by CVE-2024-21550?
CVE-2024-21550 affects SteVe versions up to 3.5.1, 3.6.0, and 3.7.0.
What kind of attack does CVE-2024-21550 enable?
CVE-2024-21550 enables attackers to inject arbitrary HTML and JavaScript code via WebSockets.
What is SteVe in the context of CVE-2024-21550?
SteVe is an open platform that implements different versions of the OCPP protocol for managing Electric Vehicle charge points.