1 results (0.004 seconds)

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

02 Aug 2021 — OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page. El runtime de OpenPLC versiones V3 hasta 14-03-2016, permite un ataque de tipo XSS almacenado por medio del Nombre del Dispositivo a la página Add New Device del servidor web • https://www.youtube.com/watch?v=eSAqXq4m8so • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •