Description
Stored cross-site scripting (XSS) in the web interface of MiR software versions prior to 3.0.0 on MiR Robots and MiR Fleet allows execution of arbitrary JavaScript code in a victim’s browser
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 3.0.0
Any version before 3.0.0
Credits
Lockheed Martin Red Team
References
a.storyblok.com/f/230581/x/82d4989368/msa-14.pdf
supportportal.mobile-industrial-robots.com/...ecurity-guide/