VULNERABILITY INTELLIGENCE
CVE-2018-7795
CVSS score5.4 MEDIUM
EPSS probability2.32%
CISA KEVNot currently listed
Published2018-08-29
Last modified2026-06-17
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Description
A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code.
Weakness classification
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Primary references
- cybersecurity@se.com — Third Party Advisory, VDB Entry
- cybersecurity@se.com — Mitigation, Third Party Advisory, US Government Resource
- cybersecurity@se.com — Mitigation, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Mitigation, Third Party Advisory, US Government Resource
- af854a3a-2127-422b-91ae-364da2661108 — Mitigation, Vendor Advisory