xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2022-05-16T17:53:01.000724Z

Updated: 2024-09-16T17:24:08.684Z

Reserved: 2021-05-13T00:00:00

Link: CVE-2021-33021

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-05-16T18:15:08.287

Modified: 2022-05-25T14:43:45.797

Link: CVE-2021-33021

cve-icon Redhat

No data.