Description
A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.
Published: 2026-06-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A cross‑site scripting flaw in the Builder Component of Pilz PASvisu before 1.14.1 permits a local unauthenticated attacker to inject malicious JavaScript that can take full control of the device. This variant of CWE‑79 can be used to execute arbitrary commands or exfiltrate data, effectively giving the attacker complete device control.

Affected Systems

Pilz PASvisu (all releases prior to 1.14.1) and Pilz PMI v8xx (affected versions not specified, but any unpatched installation is potentially vulnerable).

Risk and Exploitability

The CVSS score of 7.8 indicates a high level of severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local; an attacker would need access to the device’s local network or console to reach the Builder Component and inject the malicious script.

Generated by OpenCVE AI on June 22, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Pilz PASvisu to version 1.14.1 or later, and check for a similar update for Pilz PMI v8xx.
  • Restrict local network access to the Builder Component and enforce least‑privilege policies to prevent unauthenticated use.
  • Deploy a web application firewall or input‑validation layer to block malicious script injection if a patch is unavailable.

Generated by OpenCVE AI on June 22, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 22 Jun 2026 10:00:00 +0000

Type Values Removed Values Added
Description A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.
Title Pilz: XSS vulnerability in Pilz PASvisu and PMI v8xx
First Time appeared Pilz
Pilz pasvisu
Pilz pmi V8xx
Weaknesses CWE-79
CPEs cpe:2.3:a:pilz:pasvisu:*:*:*:*:*:*:*:*
cpe:2.3:a:pilz:pmi_v8xx:*:*:*:*:*:*:*:*
Vendors & Products Pilz
Pilz pasvisu
Pilz pmi V8xx
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-06-22T09:06:52.570Z

Reserved: 2023-10-13T06:40:49.611Z

Link: CVE-2023-45795

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-22T11:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')