#VU63070 Input validation error in Desigo PXC4 and Desigo PXC5 - CVE-2022-24039
Published: May 11, 2022
Desigo PXC4
Desigo PXC5
Siemens
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to the "addCell" JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of the XLS report document. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.