Vulnerabilities (CVE)

Filtered by vendor Schneider-electric Subscribe
Filtered by product Webreports
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-7571 1 Schneider-electric 1 Webreports 2022-01-31 3.5 LOW 5.4 MEDIUM
A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a Cross-Site Scripting reflected attack against other WebReport users.
CVE-2020-7573 1 Schneider-electric 1 Webreports 2022-01-31 6.4 MEDIUM 6.5 MEDIUM
A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker being able to access a restricted web resources due to improper access control.
CVE-2020-7570 1 Schneider-electric 1 Webreports 2022-01-31 3.5 LOW 5.4 MEDIUM
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Cross-Site Scripting stored attack against other WebReport users.