CVE-2023-2266
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Nov 30, 2023
Updated: Dec 6, 2023
CWE ID 917
Summary
CVE-2023-2266 is a web page generation vulnerability affecting Schweitzer Engineering Laboratories' SEL-411L system. This issue permits an attacker to inject malicious scripts, leading to cross-site scripting (XSS) attacks. Unauthorized and authenticated users are at risk, as the flaw lies in the improper handling of user input. Users are advised to consult the product Instruction Manual Appendix A dated August 30, 2023, for further details.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Apache Software Foundation