CVE-2020-7570: Schneider Electric Webreports
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Cross-Site Scripting stored attack against other WebReport users.
Affected products
- Schneider Electric Webreports: from 1.9, up to and including 3.1
Published 2020-11-19. Last modified 2026-06-17.