CVE-2018-19615

MEDIUM

Rockwell Automation Allen-Bradley PowerMonitor 1000 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-19615. PoCs published by Luca.Chiou.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Rockwell Automation Allen-Bradley PowerMonitor 1000. The vulnerability allows an attacker to inject malicious JavaScript code into the user account parameter, which is stored in the database and executed when accessed.

Description

Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a targeted user’s web browser to gain access to the affected device.

Exploits (1)

exploitdb WORKING POC
by Luca.Chiou · textwebappshardware
https://www.exploit-db.com/exploits/45928

This exploit demonstrates a stored XSS vulnerability in Rockwell Automation Allen-Bradley PowerMonitor 1000. The vulnerability allows an attacker to inject malicious JavaScript code into the user account parameter, which is stored in the database and executed when accessed.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Rockwell Automation Allen-Bradley PowerMonitor 1000 1408-EM3A-ENT B
Auth required
Prerequisites: Access to the Security.shtm page · Valid credentials to add a new user
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-19-050-04
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45928/
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106333
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108538

Scores

CVSS v3 6.1
EPSS 0.0330
EPSS Percentile 87.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
rockwellautomation/powermonitor_1000_firmware 1408-em3a-ent_b
Published Dec 26, 2018
Tracked Since Feb 18, 2026