Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2020-7571
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a Cross-Site Scripting reflected attack against other WebReport users.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Schneider Electric EcoStruxure Building Operation WebReports 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
施耐德电气 Schneider Electric EcoStruxure Building Operation WebReports是法国施耐德电气公司的一个企业级楼宇控制系统的基于Web的控制平台。 Schneider Electric EcoStruxure Building Operation WebReports 1.9版本至3.1版本存在跨站脚本漏洞,攻击者可利用该漏洞远程注入任意Web脚本或HTML由于不正确的卫生处理的用户提供的数据,实现跨站点脚本攻击其他WebReport用户反映出来。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-EcoStruxure Building Operation WebReports V1.9 - V3.1 EcoStruxure Building Operation WebReports V1.9 - V3.1 -
II. Public POCs for CVE-2020-7571
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2020-7571
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2020-7571

No comments yet


Leave a comment