Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A CWE-79 Improper Neutralization of Input During Web Page Generation (�Cross-site Scripting�) vulnerability exists that could allow an attacker to impersonate the user who manages the charging station or carry out actions on their behalf when crafted malicious parameters are submitted to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多款Schneider Electric产品跨站脚本漏洞
Vulnerability Description
Schneider Electric EVlink City等都是法国施耐德电气(Schneider Electric)公司的电动汽车充电站的一款充电解决方案。 多款Schneider Electric产品存在跨站脚本漏洞,该漏洞允许攻击者冒充管理充电站的用户,或精心设计的恶意参数被提交到充电站web服务器时代表用户执行操作。以下产品及版本受到影响:EVlink City EVC1S22P4 / EVC1S7P4 (R8 V3.4.0.2之前所有版本 ), EVlink Parking EVW2 / EV
CVSS Information
N/A
Vulnerability Type
N/A