CVE-2011-4038

Invensys Wonderware HMI Reports <3.42.835.0304 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Scores

EPSS 0.0203
EPSS Percentile 83.6%

Classification

CWE
CWE-79
Status published

Affected Products (6)

dreamreport/dream_report < 3.43
dreamreport/dream_report
dreamreport/dream_report
dreamreport/dream_report
invensys/wonderware_hmi_reports < 3.42.835.0304
n/a/n/a

Timeline

Published Feb 10, 2012
Tracked Since Feb 18, 2026