vendor:
                    ABB Cylon Aspect
                by:
                    Gjoko 'LiquidWorm' Krstic
                6.1
                        CVSS
                    HIGH
                    Stored Cross-Site Scripting
                    79
                        CWE
                    Product Name: ABB Cylon Aspect
                    Affected Version From:  NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio <=3.08.02
                    Affected Version To:  
                    Patch Exists: NO
                    Related CWE: CVE-2021-XXXXX
                    CPE:  a:abb_ltd:aspect:3.08.02
                    Platforms Tested:  GNU/Linux, Intel Processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
                    2021
                    ABB Cylon Aspect 3.08.02 Stored Cross-Site Scripting Vulnerability
The ABB Cylon Aspect BMS/BAS controller in versions <=3.08.02 is vulnerable to an authenticated stored cross-site scripting (XSS) flaw. An attacker can upload a malicious .txt file with XSS payload, which when stored on the server, can be served back to users. By injecting client-side scripts, attackers can execute arbitrary code in the context of any user accessing the infected file or related web page (license.php). Bypassing file upload checks requires including the Variant string in the request.
Mitigation:
					To mitigate this vulnerability, restrict file uploads to only allow specific file types, implement proper input validation, sanitize user inputs, and regularly update to the latest patched versions of the ABB Cylon Aspect software.