CVE-2023-31158
CVSS V2 None
CVSS V3 None
Description
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code.
See SEL Service Bulletin dated 2022-11-15 for more details.
Overview
- CVE ID
- CVE-2023-31158
- Assigner
- security@selinc.com
- Vulnerability Status
- Received
- Published Version
- 2023-05-10T20:15:10
- Last Modified Date
- 2023-05-10T20:15:10
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://selinc.com/support/security-notifications/external-reports/ | |
https://www.nozominetworks.com/blog/ |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-31158 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-31158 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-05-10 21:01:25 | Added to TrackCVE | |||
2023-05-10 21:01:30 | Weakness Enumeration | new |