Impact
A stored cross‑site scripting flaw in FactoryTalk DataMosaix Private Cloud allows an authenticated user with high privileges to inject malicious JavaScript into workflow configuration fields. The unneutralized input is permanently saved on the server, so any subsequent user who views the affected page will have the script executed in their browser. This can lead to session hijacking, credential theft, or forced redirection to attacker‑controlled sites.
Affected Systems
All installations of Rockwell Automation FactoryTalk DataMosaix Private Cloud running versions earlier than 8.03 are potentially affected, as the remediation provided by the vendor recommends upgrading to 8.03 or later.
Risk and Exploitability
The CVSS score of 8.4 classifies the vulnerability as high severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Likely exploitation requires an authenticated account with elevated privileges to submit the malicious payload through the workflow interface; after injection, the attack remains dormant until another authorized user accesses the page, at which point the stored script runs in that user’s browser.
OpenCVE Enrichment