Endress+Hauser MEAC300-FNADE4 Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting vulnerability has been identified in the Endress+Hauser MEAC300-FNADE4 web application, all firmware versions. This issue allows an authenticated administrator to inject JavaScript into the dashboard name, which is executed when the dashboard is loaded. The vulnerability arises because the application does not properly sanitize input before displaying it, creating an opportunity for script injection.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser.
Remediation
Users are advised to update to the latest version of the MEAC300-FNADE4 firmware. Instructions for updating can be found on the Endress+Hauser website or by contacting Endress+Hauser support.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
