cross-site scripting (XSS) vulnerability exists in the SVG version of System
Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that
enables a remote attacker to execute arbitrary JavaScript code in the context
of the attacked user’s browser session.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
An update is available that resolves a vulnerability in the product versions listed above.
Vendor Workaround
Do not use Hyperlinks provided by untrusted 3rd party to access the SDM. Hyperlinks may be provided via: * Emails from unknown users * Social media channels * Messaging services * Webpages with comment functionality * QR Codes The use of external Web Application Firewalls (WAF) can mitigate attacks using reflected cross-site scripting.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58286 | A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session. |
No history.
Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2024-08-02T08:21:17.060Z
Reserved: 2023-11-08T10:17:50.175Z
Link: CVE-2023-6028
Updated: 2024-08-02T08:21:17.060Z
Status : Modified
Published: 2024-02-05T18:15:51.670
Modified: 2024-11-21T08:43:00.503
Link: CVE-2023-6028
No data.
OpenCVE Enrichment
No data.
EUVD