CVE-2017-14850: Orpak Siteomat
Medium severity, CVSS 6.1. EPSS: 1.7% chance of exploitation in the next 30 days.
All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. An attacker with access to the web interface is able to hijack sessions or navigate victims outside of SiteOmat, to a malicious server owned by him.
Affected products
- Orpak Siteomat: before 6.4.414.084 (fixed in 6.4.414.084)
Published 2019-06-03. Last modified 2026-06-17.