CVE-2021-27887
14.06.2021, 22:15
Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victims browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and prior versions; 5.2 version 5.2.0.3 and prior versions; 5.1 version 5.1.0.6 and prior versions.
Vendor | Product | Version |
---|---|---|
hitachiabb-powergrids | ellipse_asset_performance_management | 5.1.0.0 ≤ 𝑥 ≤ 5.1.0.6 |
hitachiabb-powergrids | ellipse_asset_performance_management | 5.2.0.0 ≤ 𝑥 ≤ 5.2.0.3 |
hitachiabb-powergrids | ellipse_asset_performance_management | 5.3.0.0 ≤ 𝑥 ≤ 5.3.0.1 |
𝑥
= Vulnerable software versions