Contec CONPROSYS HMI System
cpe:2.3:a:contec:conprosys_hmi_system:*:*:*:*:*:*:*
- < 3.7.7
A reflected cross-site scripting vulnerability has been identified in the Contec CONPROSYS HMI System (CHS) versions prior to 3.7.7. This issue arises in the getqsetting.php functionality, allowing for the execution of arbitrary scripts in the browser upon interaction.
Exploitation of this vulnerability allows for the execution of arbitrary scripts in the web browser of the user accessing the application.
Users are advised to update to CONPROSYS HMI System (CHS) version 3.7.7 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.