VendorsSchneider Electricecostruxure_power_monitoring_expert2021
Vulnerabilities

Schneider Electric EcoStruxure Power Monitoring Expert 2021

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2023-5986
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.
Published 2023-11-15 · Modified
8.2EPSS 0.005
CVE-2023-5987
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
Published 2023-11-15 · Modified
6.1EPSS 0.004