Unrated severityNVD Advisory· Published Sep 2, 2025· Updated Sep 2, 2025
Stored XSS by uploading a specially crafted floor plan file
CVE-2025-52546
Description
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can inject a stored XSS to the floorplan web page.
Affected products
1- Copeland LP/E3 Supervisory Controlv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.