CyberRota Analysis
AI-GeneratedThe Loytec OPC XML-DA server in various products is vulnerable to stored cross-site scripting, allowing unauthenticated remote attackers to inject malicious JavaScript into an administrator's browser through a crafted `User-Agent` header in a specific request. This vulnerability could lead to session hijacking, credential theft, and unauthorized device reconfiguration. Organizations using affected Loytec products should prioritize this issue to mitigate potential security risks.
Original NVD Description
Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request.