Description
The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue affects CONPROSYS HMI System (CHS): before 3.7.7.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 3.7.7
Credits
Alex Williams of Converge Technology Solutions
References
jvn.jp/en/vu/JVNVU92266386/
www.vulncheck.com/...ries/conprosys-hmi-system-reflected-xss