OSIsoft PI Web API Privilege Escalation and Cross Site Scripting Vulnerabilities
BID:103396
CVE-2018-7500 | CVE-2018-7508 |Info
OSIsoft PI Web API Privilege Escalation and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 103396 |
| Class: | Unknown |
| CVE: |
CVE-2018-7500 CVE-2018-7508 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2018 12:00AM |
| Updated: | Mar 13 2018 12:00AM |
| Credit: | OSIsoft |
| Vulnerable: |
OSISoft PI Web API 2017 R2 0 OSISoft PI Web API 2016 R2 0 |
| Not Vulnerable: |
OSISoft PI Web API 2017 R2 SP1 0 OSISoft PI Vision 2017 R2 Update 1 OSISoft PI AF Services 2017 R2 Update 1 0 |
Discussion
OSIsoft PI Web API Privilege Escalation and Cross Site Scripting Vulnerabilities
OSIsoft PI Web API is prone to a privilege escalation vulnerability and a cross-site scripting vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or gain elevated privileges and perform unauthorized actions. This may aid in further attacks.
OSIsoft PI Web API 2017 R2 and prior are vulnerable.
OSIsoft PI Web API is prone to a privilege escalation vulnerability and a cross-site scripting vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or gain elevated privileges and perform unauthorized actions. This may aid in further attacks.
OSIsoft PI Web API 2017 R2 and prior are vulnerable.
Exploit / POC
OSIsoft PI Web API Privilege Escalation and Cross Site Scripting Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].