Impact
An input validation flaw in the si‑map component of Siemens Element maps‑ng allows unsanitized user‑controlled input in the points property to be rendered as a tooltip label for map pins. When a crafted URL containing malicious script is loaded and the pin is hovered, the script executes in the victim’s browser context, potentially leading to credential theft, phishing, or other client‑side attacks. The vulnerability is a classic reflected XSS exploitation (CWE‑79) and delivers code execution without the need for elevated privileges on the server.
Affected Systems
The flaw exists in Element maps‑ng V47 for all releases below V47.12.3, in Element maps‑ng V48 for all releases below V48.11.3, and in Element maps‑ng V49 for all releases below V49.16.1. Only Siemens customers using these specific product versions are impacted.
Risk and Exploitability
The CVSS score of 7 indicates moderate to high severity, and the exploit is feasible in a typical web‑browser scenario. No EPSS score is available, and the vulnerability is not yet listed in the CISA KEV catalog, but the nature of XSS suggests attackers could create malicious links that appear benign. The attack vector is reflected, locally or remotely, via a crafted URL that a user opens in a browser that has the map component rendered.
OpenCVE Enrichment