Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and prior versions; 5.2 version 5.2.0.3 and prior versions; 5.1 version 5.1.0.6 and prior versions.
Una vulnerabilidad de tipo Cross-site Scripting (XSS) en el panel principal de las versiones de Ellipse APM, permite a un usuario autenticado o a una aplicación integrada inyectar datos maliciosos en la aplicación que pueden ser ejecutados en el navegador de la víctima. Este problema afecta a: Hitachi ABB Power Grids Ellipse APM versiones 5.3, 5.3.0.1 y anteriores; versiones 5.2, 5.2.0.3 y anteriores; versiones 5.1, 5.1.0.6 y anteriores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | REQUIRED |
| Scope | CHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | LOW |
| Availability Impact | NONE |
AV:N/AC:M/Au:S/C:N/I:P/A:N
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | SINGLE |
| Confidentiality Impact | NONE |
| Integrity Impact | PARTIAL |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-79
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| hitachiabb-powergrids | ellipse_asset_performance_management | * | <built-in method update of dict object at 0x72a9b0cd61c0> | Application |
| hitachiabb-powergrids | ellipse_asset_performance_management | * | <built-in method update of dict object at 0x72a9b0cd4b40> | Application |
| hitachiabb-powergrids | ellipse_asset_performance_management | * | <built-in method update of dict object at 0x72a9b0cd76c0> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:hitachiabb-powergrids:ellipse_asset_performance_management:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:hitachiabb-powergrids:ellipse_asset_performance_management:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:hitachiabb-powergrids:ellipse_asset_performance_management:*:*:*:*:*:*:*:* |