Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19199 | SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface. |
Tue, 13 Aug 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Steve-community
Steve-community steve |
|
| CPEs | cpe:2.3:a:steve-community:steve:*:*:*:*:*:*:*:* cpe:2.3:a:steve-community:steve:3.6.0:*:*:*:*:*:*:* cpe:2.3:a:steve-community:steve:3.7.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Steve-community
Steve-community steve |
Mon, 12 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface. | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-12T15:20:03.103Z
Reserved: 2023-12-22T12:33:20.128Z
Link: CVE-2024-21550
Updated: 2024-08-12T15:19:55.948Z
Status : Analyzed
Published: 2024-08-12T15:15:19.903
Modified: 2024-08-13T17:33:13.537
Link: CVE-2024-21550
No data.
OpenCVE Enrichment
No data.
EUVD