The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injection and execution of malicious scripts when abused by bad actors.
History

Fri, 13 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Eaton
Eaton foreseer Electrical Power Monitoring System
CPEs cpe:2.3:a:eaton:foreseer_electrical_power_monitoring_system:*:*:*:*:*:*:*:*
Vendors & Products Eaton
Eaton foreseer Electrical Power Monitoring System
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 13 Sep 2024 17:00:00 +0000

Type Values Removed Values Added
Description The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injection and execution of malicious scripts when abused by bad actors.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Eaton

Published: 2024-09-13T16:46:51.010Z

Updated: 2024-09-13T17:35:46.770Z

Reserved: 2024-04-03T11:17:01.662Z

Link: CVE-2024-31414

cve-icon Vulnrichment

Updated: 2024-09-13T17:35:42.746Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-13T17:15:11.707

Modified: 2024-09-19T18:48:25.893

Link: CVE-2024-31414

cve-icon Redhat

No data.