Vulnerability Description
Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parameter, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Softing | Opc Toolbox | <= 4.10.1.13035 |
Related Weaknesses (CWE)
References
- https://www.gruppotim.it/redteamExploitThird Party Advisory
- https://www.gruppotim.it/redteamExploitThird Party Advisory
FAQ
What is CVE-2021-29661?
CVE-2021-29661 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parameter, resulting in JavaScript payload injection into the trace file. This payload...
How severe is CVE-2021-29661?
CVE-2021-29661 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-29661?
Check the references section above for vendor advisories and patch information. Affected products include: Softing Opc Toolbox.