← back
CVE-2023-31160

Improper Neutralization of Input During Web Page Generation

CVSS 4.3 MEDIUMEPSS 0.4%CWE-79
In short

The SEL RTAC web interface fails to properly filter user input, allowing an authenticated attacker to inject malicious scripts that execute in other users' browsers. This can compromise sensitive control system data or actions.

Technical detail

CWE-79 Stored or Reflected XSS vulnerability in SEL RTAC web interface lacks input sanitization during page generation. Attack vector requires prior authentication; attacker can inject arbitrary JavaScript to be executed in victim's session, potentially leading to unauthorized commands or data theft in the industrial control environment.

Summary generated and translated by AI from the official description.
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin dated 2022-11-15 for more details.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →