The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:03:33.651Z
Reserved: 2021-04-23T00:00:00
Link: CVE-2021-31682
No data.
Status : Modified
Published: 2021-10-22T12:15:07.923
Modified: 2024-11-21T06:06:07.587
Link: CVE-2021-31682
No data.
OpenCVE Enrichment
No data.
Weaknesses