Record summary

CVE-2019-11370 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBCarel pCOWeb < B1.2.1 - Cross-Site ScriptingExploitDB exploitby Luca.ChiouNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMCarel pCOWeb <B1.2.4 - Cross-Site ScriptingCVSS 5.4

Carel pCOWeb prior to B1.2.4 is vulnerable to stored cross-site scripting, as demonstrated by the config/pw_snmp.html "System contact" field.

Impact

Allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions.

Remediation

Apply the latest patch or upgrade to a version that addresses the vulnerability.

WeaknessesCWE-79
Authorsarafatansari
Template tagscvecve2019pcowebxsscareledbvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:carel:pcoweb_card_firmware:*:*:*:*:*:*:*:*
Shodan: http.html:"pCOWeb"
Shodan: http.html:"pcoweb"
FOFA: body="pcoweb"

Source: ProjectDiscovery

References

3