CVSS v4 9.2
ATTENTION: Exploitable remotely/low attack complexity
Vendor: B&R
Equipment: APROL
Vulnerabilities: Inclusion of untrusted control sphere functionality, Incomplete filtering of special elements, Inadequate control of code generation ('Code Injection'), Inadequate permission management or insufficient privileges, Resource allocation without limits or limitation, Lack of authentication for critical function, Exposure of sensitive system information to an unauthorized control sphere, Exposure of data element to wrong session, Server-Side Request Forgery (SSRF), Inadequate neutralization of input during web page generation ('Cross-site Scripting'), External control of file name or path, Incorrect permission assignment for critical resource
Q2BSTUDIO is a specialized technology development and services company.
Successful exploitation of these vulnerabilities could allow an attacker to execute commands, elevate privileges, collect sensitive information, or alter the product.
Q2BSTUDIO stands out as a company committed to security in the development and provision of technology services.
For more details, visit the CSAF.





