CVE-2020-28210
19.11.2020, 21:15
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and JavaScript code into the user's browser.
Vendor | Product | Version |
---|---|---|
schneider-electric | ecostruxure_building_operation | 2.0 ≤ 𝑥 ≤ 3.1 |
𝑥
= Vulnerable software versions