CVE-2023-2266

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Nov 30, 2023
Updated: Dec 6, 2023
CWE ID 917

Summary

CVE-2023-2266 is a web page generation vulnerability affecting Schweitzer Engineering Laboratories' SEL-411L system. This issue permits an attacker to inject malicious scripts, leading to cross-site scripting (XSS) attacks. Unauthorized and authenticated users are at risk, as the flaw lies in the improper handling of user input. Users are advised to consult the product Instruction Manual Appendix A dated August 30, 2023, for further details.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share