Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-15-300-02 | Patch Third Party Advisory US Government Resource |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: icscert
Published: 2015-10-28T10:00:00
Updated: 2015-10-28T04:57:01
Reserved: 2015-08-17T00:00:00
Link: CVE-2015-6494
JSON object: View
NVD Information
Status : Analyzed
Published: 2015-10-28T10:59:16.717
Modified: 2015-10-28T21:04:00.990
Link: CVE-2015-6494
JSON object: View
Redhat Information
No data.
CWE