Vulnerabilities · InfosecFeed Brief
Johnson Controls Metasys
Vulnerabilities
What you need to know
Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access. The following versions of Johnson Controls Metasys are…
Source transparency
Read the original report at CISA Alerts ↗
This is an InfosecFeed curated brief based on reporting from CISA Alerts. InfosecFeed does not claim ownership of the original reporting.