A
cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local access to the connector admin portal to persist arbitrary JavaScript code that will be executed by other users who visit affected pages.
References
Configurations
No configuration.
History
16 Jun 2025, 12:32
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
12 Jun 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-06-12 20:15
Updated : 2025-06-16 12:32
NVD link : CVE-2025-4417
Mitre link : CVE-2025-4417
CVE.ORG link : CVE-2025-4417
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')