Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-6528


CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.


Published

2024-07-11T09:15:04.867

Last Modified

2024-11-21T09:49:48.730

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System schneider-electric modicon_m241_firmware * Yes
Hardware schneider-electric modicon_m241 - No
Operating System schneider-electric modicon_m251_firmware * Yes
Hardware schneider-electric modicon_m251 - No
Operating System schneider-electric modicon_m258_firmware * Yes
Hardware schneider-electric modicon_m258 - No
Operating System schneider-electric modicon_m262_firmware * Yes
Hardware schneider-electric modicon_m262 - No
Operating System schneider-electric modicon_lmc058_firmware * Yes
Hardware schneider-electric modicon_lmc058 - No

References