CVE-2024-31414
The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injection and execution of malicious scripts when abused by bad actors.
Published:Sep 13, 2024
Last Modified:Sep 19, 2024
EPS:Sep 13, 2024
EPSS Score:0.00249
CVSS Score:6.7
Affected Products
Vendor
Product
Action
Vendor
Eaton
Product
Foreseer Electrical Power Monitoring System
Eaton
Foreseer Electrical Power Monitoring System
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
