CVE-2020-7571: Schneider Electric Webreports

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a Cross-Site Scripting reflected attack against other WebReport users.

Affected products

Published 2020-11-19. Last modified 2026-06-17.