CVE-2017-14850
Dashboard / Vulnerabilities / CVE-2017-14850
CVE-2017-14850
Published: 3 Jun 2019Last Modified: 10 Mar 2026
Summary:
Details: All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. An attacker with access to the web interface is able to hijack sessions or navigate victims outside of SiteOmat, to a malicious server owned by him.
References: , http://www.securityfocus.com/bid/108167, https://ics-cert.us-cert.gov/advisories/ICSA-19-122-01, https://www.orpak.com
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
