A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2023-050/ |
|
History
Mon, 22 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability. | |
| Title | XSS vulnerability in Pilz PASvisu and PMI v8xx | |
| First Time appeared |
Pilz
Pilz pasvisu Pilz pmi V8xx |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:pilz:pasvisu:*:*:*:*:*:*:*:* cpe:2.3:a:pilz:pmi_v8xx:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Pilz
Pilz pasvisu Pilz pmi V8xx |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-06-22T09:04:55.857Z
Reserved: 2023-10-13T06:40:49.611Z
Link: CVE-2023-45796
Updated: 2026-06-22T15:39:09.641Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T13:45:05Z
Weaknesses