vendor:
ABB Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Stored Cross-Site Scripting
79
CWE
Product Name: ABB Cylon Aspect
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware: <=3.08.02
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2024-6516
CPE: a:abb_ltd:cylon_aspect:3.08.02
Platforms Tested: GNU/Linux, Intel Processors, PHP, AspectFT Automation, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2024
ABB Cylon Aspect 3.08.02 Stored Cross-Site Scripting
The ABB BMS/BAS controller in ABB Cylon Aspect 3.08.02 allows authenticated users to store malicious scripts. By manipulating the 'host' POST parameter, an attacker can inject arbitrary HTML/JS code into the application. This can lead to the execution of unauthorized code within the user's browsing session.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user inputs to prevent script injection attacks. Regular security updates and monitoring for suspicious activities can also help in early detection and prevention of such exploits.