SUBNET PowerSYSTEM Center Cross-site Scripting
Vulnerability Description
SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic files that could propagate out of the system and reach users who are subscribed to email notifications.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-32659
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- SUBNET Solutions reported these vulnerabilities to CISA.
More from SUBNET Solutions Inc.
View All →Affected Vendor
SUBNET Solutions Inc.
View all reports →