CVE-2025-27448
The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded.
Vendor
Product
CWE
Yayın Tarihi
2025-07-03 12:15:22
Güncelleme
2026-02-06 14:38:25
Source Identifier
psirt@sick.de
KEV Date Added
-
Kategoriler
Referanslar
https://sick.com/psirt
https://sick.com/psirt
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
https://www.endress.com
https://www.first.org/cvss/calculator/3.1
https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json
https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf