Vulnerability Details CVE-2020-28210
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and JavaScript code into the user's browser.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.2%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-28210
-
cpe:2.3:a:schneider-electric:ecostruxure_building_operation:2.0
-
cpe:2.3:a:schneider-electric:ecostruxure_building_operation:3.1