Headline
CVE-2022-4286
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.
%PDF-1.7 %���� 1 0 obj <>/Metadata 446 0 R/ViewerPreferences 447 0 R>> endobj 2 0 obj <> endobj 3 0 obj <>/ExtGState<>/XObject<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI] >>/MediaBox[ 0 0 595.32 842.04] /Contents 4 0 R/Group<>/Tabs/S/StructParents 0>> endobj 4 0 obj <> stream x��\Ko������ ��@ 0i���������a��F9�ߧ�_�&�G# �؇�Cv=�_U��r����ow���������ݧ����|y�������~�������ǻ��O����g�����_� C���������hڑNZ�s��z"�o��g�C�x~��=?�����۷����ä���Q�3D����<��#%�ÿa�������f������Å1xK�t�:?�B9?;�1�{) �;� c� �W�$r�����1�U{��ȴ��x9f�2�S�d�yEV��Io[j���~i�i�C}�+Z��9�L��e�|��� �Q�ኑ�UdY�W�"�ާ�=�j�܀Z()L[�E��h���8������du ӆ c�Aq5�n H�!��+�7ߥeV�W–�>lՈ^���bV0:x>�y�Mֻ�� k����4���"��x��Sj����’�/O�;�Q�Ho��n?9E��K���]�5��a�W�(�~��ezf��nx���i�]6������K��<==/�A�yZK�Z*o|�s1����p�=��*���ہb��������2���~��i���a~%T�ۭ���’ZM(oW�2��"� �c�4����k�w�!8�me�i�rM����7:)��_�}�nO(ů����.N)��bۅo64J�V l�"Hm1�ci�@J�6����9����bv�w���I �� �)ot��e�9�wN�N�a-�d6b01D���[�Rp�к�’��5�{�P��HR�7D�8yiz�a�k��Z���L��]�Z$:����R�U�I ����`�J�JwB�� y�Q�ff�JvZ��Z��*hU^B)xH�r����ߑ���$�7�;����×��{*��S5�]~�z��j�i�þ#�?�=>t��?^����oC?C��"��&�Lz�9|��!��ךj��Xm’xD�Zǖu� ,�]�F�Dy���{���X+zJڜ��ά�9�מ���;ӏ��"��,�q�CF�p��}�2�Q�xو�F��*�����f&a�fFl3j4�k�����%ڞ� ��:HA`�k�`]�q�e���.�<����p8��+;g&���+A<���z�x|���e#+�=ڶ�!�1V W��(��}5�"�p�Sq��[��Gx����h�7�40Q�QHk�)��M�*E�{B�!y ��$��_�����6%ޜ� �S�TZC�@E���=���>�c&z�Ε6����Y�G�eQx��"م�����=qs��&TށΩ���P���CLWnX��c��"%CM��c"�^�1�V�4 \�R��� �]H�n�jv�Cw줽��� ��A������5�&b<��4�IB�c?��^P�
Related news
B&R Systems Diagnostics Manager versions above or equal to 3.00 and below or equal to C4.93 suffer from a cross site scripting vulnerability.
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.