CVE-2024-6528

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/07/2024
Last modified:
12/07/2024

Description

CWE-79: Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site<br /> Scripting&amp;#39;) vulnerability exists that could cause a vulnerability leading to a cross-site scripting<br /> condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a<br /> page containing the injected payload.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:schneider-electric:modicon_m241_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m241:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:modicon_m251_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m251:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:modicon_m258_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m258:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:modicon_m262_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m262:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:modicon_lmc058_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_lmc058:-:*:*:*:*:*:*:*