CVE-2018-18991
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker to send a crafted URL that contains JavaScript, which can be reflected off the web application to the victim's browser.
Affected products
n/a · SCADA WebServer