CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. It affects Java. Exploitation may require the attacker to be authenticated.
CVE
CVE-2021-29661
Severity
MEDIUM
CVSS
5.4
EPSS
0.60%
Java
Original NVD Description
Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parameter, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it.
Related CVEs
Other vulnerabilities affecting the same vendor(s)