Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting. The vulnerability exists due to insufficient validation of user input and improper encoding of the output for certain resources within the IPP software.
References
Configurations
Information
Published : 2022-04-19 14:15
Updated : 2022-04-27 11:28
NVD link : CVE-2021-23283
Mitre link : CVE-2021-23283
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
eaton
- intelligent_power_protector