cve/2021/CVE-2021-27416.md

18 lines
1005 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2021-27416](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27416)
![](https://img.shields.io/static/v1?label=Product&message=Ellipse%20Enterprise%20Asset%20Management%20(EAM)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%3D%209.0.25%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Cross-site%20Scripting%20(XSS)&color=brighgreen)
### Description
An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 by tricking a user to click on a link containing malicious code that would then be run by the web browser. This can result in the compromise of confidential information, or even the takeover of the users session.
### POC
#### Reference
- https://search.abb.com/library/Download.aspx?DocumentID=9AKK107991A7777&LanguageCode=en&DocumentPartId=&Action=Launch
#### Github
No PoCs found on GitHub currently.