Impact
This vulnerability, a client‑side XSS (CWE-79) attack, permits arbitrary JavaScript execution within the web browser of a PIMBoards user who clicks a malicious link. This can be leveraged to steal credentials, deface content or launch additional attacks against that user’s session.
Affected Systems
AVEVA Pipeline Integrity Monitor is affected. All versions prior to 2025 SP1 P2 are vulnerable; the vendor recommends upgrading to 2025 SP1 P2 or newer. Project files from older versions, especially those that cannot be migrated, pose a risk if left unchecked.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS is not reported, so exploitation likelihood is unknown. The vulnerability is not listed in CISA’s KEV catalog. Because the exploit requires a user to click a malicious link, it is a social‑engineering attack vector that could deliver malware or capture credentials, potentially enabling lateral movement for an attacker who gains access to an administrative account.
OpenCVE Enrichment