VYPR
Critical severity9.0NVD Advisory· Published Jun 23, 2020· Updated Jun 17, 2026

CVE-2020-12021

CVE-2020-12021

Description

In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remotely execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Osisoft/Pi Webapi3 versions
    cpe:2.3:a:osisoft:pi_web_api:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:osisoft:pi_web_api:*:*:*:*:*:*:*:*range: <=2019
    • cpe:2.3:a:osisoft:pi_web_api:2019:patch_1:*:*:*:*:*:*
    • (no CPE)range: <=2019 Patch 1 (1.12.0.6346)
  • OSIsoft/PI Web APIdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.