CVE Published: 17/10/2024 |
CVE Updated: 17/10/2024 |
CVE Year: 2024 Source: icscert |
Vendor: LCDS - Leão Consultoria e Desenvolvimento de Sistemas Ltda ME |
Product: LAquis SCADA Status : PUBLISHED
CVE-2024-9414 Description
In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.
CWE-ID: CWE-79 CWE Name: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or
Cross-site Scripting
) Source: LCDS - Leão Consultoria e Desenvolvimento de Sistemas Ltda ME
Common Attack Pattern Enumeration and Classification (CAPEC)