CVE Published: 10/03/2020 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: siemens |
Vendor: Siemens |
Product: Control Center Server (CCS) Status : PUBLISHED
CVE-2019-19293 Description
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The web interface of the Control Center Server (CCS) contains a
reflected Cross-site Scripting (XSS) vulnerability
that could allow an unauthenticated remote attacker to steal sensitive data
or execute administrative actions on behalf of a legitimate administrator
of the CCS web interface.
Metrics
CVSS Version: 3.1 |
Base Score: 6.1 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N/E:P/RL:U/RC:C