CVE-2020-28210

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
19/11/2020
Last modified:
31/01/2022

Description

A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and JavaScript code into the user's browser.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schneider-electric:ecostruxure_building_operation:*:*:*:*:*:*:*:* 2.0 (including) 3.1 (including)


References to Advisories, Solutions, and Tools