Lucene search

K
cvelistSchneiderCVELIST:CVE-2018-7810
HistoryNov 30, 2018 - 7:00 p.m.

CVE-2018-7810

2018-11-3019:00:00
schneider
www.cve.org
3

0.001 Low

EPSS

Percentile

44.6%

An Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to craft a URL containing JavaScript that will be executed within the user’s browser, potentially impacting the machine the browser is running on.

CNA Affected

[
  {
    "product": "Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200",
    "vendor": "Schneider Electric SE",
    "versions": [
      {
        "status": "affected",
        "version": "Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

44.6%

Related for CVELIST:CVE-2018-7810