VYPR
Unrated severityNVD Advisory· Published Nov 15, 2021· Updated Sep 17, 2024

AzeoTech DAQFactory

CVE-2021-42703

Description

This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting vulnerability in Advantech WebAccess HMI Designer allows attacker to hijack user sessions and perform malicious browser actions.

Vulnerability

A cross-site scripting (XSS) vulnerability exists in Advantech WebAccess HMI Designer versions prior to 2.1.11.0 [1]. The flaw allows an attacker to inject malicious JavaScript code, which is executed in the context of the user's browser session. The vulnerability is triggered when a user opens a specially crafted project file or interacts with a malicious web page designed to exploit the XSS condition.

Exploitation

An attacker must craft a malicious project file or web page containing the JavaScript payload and convince the user to open it (user interaction is required). No authentication or special network position is needed; the attack can be delivered via email, download, or other means. Once the user opens the file or page, the injected script executes in the browser, enabling the attacker to perform actions on behalf of the user.

Impact

Successful exploitation allows the attacker to hijack the user's cookies and session tokens, redirect the user to a malicious website, and perform unintended browser actions such as form submission or data exfiltration. This can lead to account takeover, information disclosure, and further compromise of the user's system.

Mitigation

Advantech has released WebAccess HMI Designer version 2.1.11.0 to address this vulnerability [1]. Users should update to this version or later. No workarounds are provided; the only mitigation is to apply the patch. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.