OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulnerability where displays that reference AF elements and attributes containing JavaScript are affected. This vulnerability requires the ability of authorized AF users to store JavaScript in AF elements and attributes.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-19-043-01 | US Government Resource Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: icscert
Published: 2019-04-08T14:30:39
Updated: 2019-04-08T14:30:39
Reserved: 2018-11-06T00:00:00
Link: CVE-2018-19006
JSON object: View
NVD Information
Status : Modified
Published: 2019-04-08T15:29:00.763
Modified: 2019-10-09T23:37:35.410
Link: CVE-2018-19006
JSON object: View
Redhat Information
No data.
CWE