CVE-2018-19615
MEDIUMRockwell Automation Allen-Bradley PowerMonitor 1000 - Code Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-19615. PoCs published by Luca.Chiou.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Rockwell Automation Allen-Bradley PowerMonitor 1000. The vulnerability allows an attacker to inject malicious JavaScript code into the user account parameter, which is stored in the database and executed when accessed.
Description
Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a targeted userâs web browser to gain access to the affected device.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Rockwell Automation Allen-Bradley PowerMonitor 1000. The vulnerability allows an attacker to inject malicious JavaScript code into the user account parameter, which is stored in the database and executed when accessed.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N