CVE-2021-22676
Summary
| CVE | CVE-2021-22676 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-10 15:15:00 UTC |
| Updated | 2021-08-17 19:39:00 UTC |
| Description | UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and unintended browser action on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1). |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590523 Advantech WebAccess Supervisory control and data acquisition (SCADA) Multiple Vulnerabilities (ICSA-21-217-04)