vendor:
ABB Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Stored Cross-Site Scripting
79
CWE
Product Name: ABB Cylon Aspect
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio <=3.08.02
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2021-XXXXX
CPE: a:abb_ltd:aspect:3.08.02
Platforms Tested: GNU/Linux, Intel Processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2021
ABB Cylon Aspect 3.08.02 Stored Cross-Site Scripting Vulnerability
The ABB Cylon Aspect BMS/BAS controller in versions <=3.08.02 is vulnerable to an authenticated stored cross-site scripting (XSS) flaw. An attacker can upload a malicious .txt file with XSS payload, which when stored on the server, can be served back to users. By injecting client-side scripts, attackers can execute arbitrary code in the context of any user accessing the infected file or related web page (license.php). Bypassing file upload checks requires including the Variant string in the request.
Mitigation:
To mitigate this vulnerability, restrict file uploads to only allow specific file types, implement proper input validation, sanitize user inputs, and regularly update to the latest patched versions of the ABB Cylon Aspect software.