Vulnerability CVE-2021-33021


Published: 2022-05-16

Description:
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ??edate?? of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://www.cisa.gov/uscert/ics/advisories/icsa-21-229-03

Copyright 2026, cxsecurity.com

 

Back to Top