An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to insert malicious code which is then executed in the context of the user’s browser session.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-54297 An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to insert malicious code which is then executed in the context of the user’s browser session.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 25 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Mar 2025 05:00:00 +0000

Type Values Removed Values Added
Description An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to insert malicious code which is then executed in the context of the user’s browser session.
Title Cross Site Scripting vulnerability in APROL Web Portal
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2025-03-25T13:18:32.467Z

Reserved: 2024-10-21T09:57:14.971Z

Link: CVE-2024-10208

cve-icon Vulnrichment

Updated: 2025-03-25T13:18:28.368Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-25T05:15:38.553

Modified: 2025-03-27T16:45:46.410

Link: CVE-2024-10208

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses