"value":"In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')",
"cweId":"CWE-79"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"LCDS - Le\u00e3o Consultoria e Desenvolvimento de Sistemas Ltda ME",
"value":"<p>LCDS recommends users update to <a target=\"_blank\" rel=\"nofollow\" href=\"https://laquisscada.com/\">version 4.7.1.611 or newer</a> versions of LAquis SCADA.</p><br>\n\n<br>"
}
],
"value":"LCDS recommends users update to version 4.7.1.611 or newer https://laquisscada.com/ \u00a0versions of LAquis SCADA."
}
],
"credits":[
{
"lang":"en",
"value":"Mounir Aarab reported this vulnerability to CISA."