CVE-2011-4038
Invensys Wonderware HMI Reports <3.42.835.0304 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Scores
EPSS
0.0203
EPSS Percentile
83.6%
Classification
CWE
CWE-79
Status
published
Affected Products (6)
dreamreport/dream_report
< 3.43
dreamreport/dream_report
dreamreport/dream_report
dreamreport/dream_report
invensys/wonderware_hmi_reports
< 3.42.835.0304
n/a/n/a
Timeline
Published
Feb 10, 2012
Tracked Since
Feb 18, 2026