Input validation error in Desigo PXC4 and Desigo PXC5 - CVE-2022-24039
Published: May 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to the "addCell" JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of the XLS report document. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Desigo PXC5
How to mitigate CVE-2022-24039
Desigo PXC5 - update to 02.20.142.10-10884