CVE-2021-34582
10.11.2021, 12:15
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTML code (XSS) through web-based management or the REST API with a manipulated certificate file.
Vendor | Product | Version |
---|---|---|
phoenixcontact | fl_mguard_1102_firmware | 1.4.0 |
phoenixcontact | fl_mguard_1102_firmware | 1.4.1 |
phoenixcontact | fl_mguard_1102_firmware | 1.5.0 |
phoenixcontact | fl_mguard_1105_firmware | 1.4.0 |
phoenixcontact | fl_mguard_1105_firmware | 1.4.1 |
phoenixcontact | fl_mguard_1105_firmware | 1.5.0 |
𝑥
= Vulnerable software versions