Vulnerabilities > Smartptt > Smartptt Scada > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-28 | CVE-2021-43930 | Unspecified vulnerability in Smartptt Scada 1.1 Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system. | 4.9 |
2022-04-28 | CVE-2021-43932 | Cross-site Scripting vulnerability in Smartptt Scada 1.1 Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page. | 6.1 |