Overview
- Description
- Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and prior versions; 5.2 version 5.2.0.3 and prior versions; 5.1 version 5.1.0.6 and prior versions.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 3.5
- Impact score
- 2.9
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:hitachiabb-powergrids:ellipse_asset_performance_management:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A51B133-F610-458A-88D4-A5B66787AD97", "versionEndIncluding": "5.1.0.6", "versionStartIncluding": "5.1.0.0" }, { "criteria": "cpe:2.3:a:hitachiabb-powergrids:ellipse_asset_performance_management:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D32AA6B-5900-460C-A8FF-5BF39A0A3E61", "versionEndIncluding": "5.2.0.3", "versionStartIncluding": "5.2.0.0" }, { "criteria": "cpe:2.3:a:hitachiabb-powergrids:ellipse_asset_performance_management:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34D123F4-E0F6-4F45-9891-D8BC35757496", "versionEndIncluding": "5.3.0.1", "versionStartIncluding": "5.3.0.0" } ], "operator": "OR" } ] } ]