Cross-site Scripting - CVE-2016-4513

 

Cross-site Scripting - CVE-2016-4513

Published: June 29, 2016 / Updated: July 12, 2020


Vulnerability identifier: #VU54
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2016-4513
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor:
Affected software:

Detailed vulnerability description

The vulnerability allows a remote attacker to inject arbitrary JavaScript.

The vulnerability exists due to boundary error when parsing HTTP requests. A remote unauthenticated attacker can steal potentially sensitive information by injecting arbitrary JavaScript in a specially crafted URL request where the response containing user data is returned to the web browser without being made safe to display.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

How to mitigate CVE-2016-4513

Schneider Electric has produced a firmware update to mitigate this vulnerability.
The PowerLogic PM8ECC firmware Version 2.651 is available at:
http://www.schneider-electric.com/ww/en/download/document/p8e02651_DOT_bin

Sources