CVE-2021-41541
Summary
| CVE | CVE-2021-41541 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-08 12:15:00 UTC |
| Updated | 2022-03-11 18:32:00 UTC |
| Description | A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The Group Management page of affected devices is vulnerable to cross-site scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could result in hijacking of the user's cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser action. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591376 Siemens Climatix POL909 Cross-Site Scripting (XSS), Improper Access Control Multiple Vulnerabilities (SSA-252466, ICSA-22-069-07)