Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/NullByte8080/CVE-2026-36226 |
|
History
Fri, 22 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting in Advantech WebAccess/SCADA Decryption Field Enables Sensitive Data Disclosure | |
| First Time appeared |
Advantech
Advantech webaccess/scada |
|
| Vendors & Products |
Advantech
Advantech webaccess/scada |
Fri, 22 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 22 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-22T17:33:38.680Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36226
Updated: 2026-05-22T17:33:34.508Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-22T20:00:13Z
Weaknesses