CVE-2026-2101: Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19
A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2101?
CVE-2026-2101 is classified as a medium severity vulnerability due to its potential to allow attackers to execute arbitrary scripts on affected systems.
How do I fix CVE-2026-2101?
To mitigate CVE-2026-2101, it is recommended to update ENOVIAvpm Web Access to a version beyond 1.19.
Which versions are affected by CVE-2026-2101?
CVE-2026-2101 affects ENOVIAvpm Versions 1 Release 16 through 1 Release 19.
What type of attack does CVE-2026-2101 enable?
CVE-2026-2101 enables reflected cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Is user authentication affected by CVE-2026-2101?
CVE-2026-2101 does not directly impact user authentication but may compromise user sessions through malicious scripts.