PcVue
cpe:2.3:a:pcvuesolutions:pcvue:*:*:*:*:*:*:*
- >= 12.0.0, <= 16.3.3
A cross-site scripting (XSS) vulnerability has been identified in the OAuth web services utilized by PcVue's WebVue, WebScheduler, TouchVue, and SnapVue features. This vulnerability affects PcVue versions 12.0.0 through 16.3.3. It may allow a remote attacker to deceive a legitimate user into loading content from an external site, particularly when user authentication fails on an unspecified application. The issue is confined to the error page of the OAuth server.
Exploitation of this vulnerability could lead to cross-site scripting, allowing for the injection of malicious scripts that could be executed in the context of the user's browser.
Users can upgrade to PcVue version 16.3.4 to address this vulnerability. For PcVue 15 users, version 15.2.14 is available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.