A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). There is a stored cross-site scripting vulnerability in the Administration Console of the affected product, that could allow an attacker with high privileges to inject Javascript code into the application that is later executed by another legitimate user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2023-11-14T11:04:21.326Z
Updated: 2024-08-02T20:37:39.392Z
Reserved: 2023-10-16T11:24:12.686Z
Link: CVE-2023-46099
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-11-14T11:15:14.840
Modified: 2024-11-21T08:27:53.853
Link: CVE-2023-46099
Redhat
No data.