Schneider-electric

Webreports

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.49%
  • Veröffentlicht 19.11.2020 22:15:15
  • Zuletzt bearbeitet 21.11.2024 05:37:23

A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification o...

  • EPSS 0.19%
  • Veröffentlicht 19.11.2020 22:15:15
  • Zuletzt bearbeitet 21.11.2024 05:37:23

A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitr...

  • EPSS 0.19%
  • Veröffentlicht 19.11.2020 22:15:15
  • Zuletzt bearbeitet 21.11.2024 05:37:23

A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web sc...

  • EPSS 0.48%
  • Veröffentlicht 19.11.2020 22:15:15
  • Zuletzt bearbeitet 21.11.2024 05:37:24

A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure ...

  • EPSS 0.2%
  • Veröffentlicht 19.11.2020 22:15:15
  • Zuletzt bearbeitet 21.11.2024 05:37:24

A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker being able to access a restricted web resources due to improper access control.