VULNERABILITY INTELLIGENCE

CVE-2018-7795

CVSS score5.4 MEDIUM
EPSS probability2.32%
CISA KEVNot currently listed
Published2018-08-29
Last modified2026-06-17
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Description

A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code.

Weakness classification

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Primary references