Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 3.9.2
Any version before 3.9.2
Credits
ABB acknowledges and thanks Psytester for responsibly disclosing the vulnerabilities and helping to verify the resolving implementation.
References
search.abb.com/...geCode=en&DocumentPartId=pdf&Action=Launch