Vulnerabilities > Smartptt > Smartptt Scada > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-04-28 CVE-2021-43930 Unspecified vulnerability in Smartptt Scada 1.1
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.
network
low complexity
smartptt
4.9
2022-04-28 CVE-2021-43932 Cross-site Scripting vulnerability in Smartptt Scada 1.1
Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.
network
low complexity
smartptt CWE-79
6.1