Home
MEDIUM: 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:NDefault status
affected
all versions (custom)
affected
Default status
affected
all versions (custom)
affected
Default status
affected
all versions (custom)
affected
Default status
affected
all versions (custom)
affected
Description
JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
all versions (custom)
all versions (custom)
all versions (custom)
all versions (custom)
References
www.sick.com/...lines_cybersecurity_by_sick_en_im0106719.pdf
www.cisa.gov/...es-tools/resources/ics-recommended-practices
www.first.org/cvss/calculator/3.1
www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json
www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf