CVE-2020-7571: Schneider Electric Webreports
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a Cross-Site Scripting reflected attack against other WebReport users.
Affected products
- Schneider Electric Webreports: from 1.9, up to and including 3.1
Published 2020-11-19. Last modified 2026-06-17.