OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulnerability where displays that reference AF elements and attributes containing JavaScript are affected. This vulnerability requires the ability of authorized AF users to store JavaScript in AF elements and attributes.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-19-043-01 US Government Resource Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2019-04-08T14:30:39

Updated: 2019-04-08T14:30:39

Reserved: 2018-11-06T00:00:00


Link: CVE-2018-19006

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-04-08T15:29:00.763

Modified: 2019-10-09T23:37:35.410


Link: CVE-2018-19006

JSON object: View

cve-icon Redhat Information

No data.

CWE