Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and prior versions; 5.2 version 5.2.0.3 and prior versions; 5.1 version 5.1.0.6 and prior versions.
References
Link | Resource |
---|---|
https://search.abb.com/library/Download.aspx?DocumentID=9AKK107991A9700&LanguageCode=en&DocumentPartId=&Action=Launch | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-03-29T00:00:00
Updated: 2021-06-14T21:23:53
Reserved: 2021-03-01T00:00:00
Link: CVE-2021-27887
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-06-14T22:15:15.797
Modified: 2021-06-22T16:14:40.570
Link: CVE-2021-27887
JSON object: View
Redhat Information
No data.
CWE