Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-27887


Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and prior versions; 5.2 version 5.2.0.3 and prior versions; 5.1 version 5.1.0.6 and prior versions.


Published

2021-06-14T22:15:15.797

Last Modified

2024-11-21T05:58:42.163

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hitachiabb-powergrids ellipse_asset_performance_management ≤ 5.1.0.6 Yes
Application hitachiabb-powergrids ellipse_asset_performance_management ≤ 5.2.0.3 Yes
Application hitachiabb-powergrids ellipse_asset_performance_management ≤ 5.3.0.1 Yes

References