CVE Published: 30/11/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: schneider |
Vendor: Schneider Electric SE |
Product: Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 Status : PUBLISHED
CVE-2018-7810 Description
An Improper Neutralization of Input During Web Page Generation (\'Cross-site Scripting\') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to craft a URL containing JavaScript that will be executed within the user\'s browser, potentially impacting the machine the browser is running on.