Execution of any zenon function in HTML5 Webclient by manipulating frontend JS code

Execution of any zenon function in HTML5 Webclient by manipulating frontend JS code

Summary

The security issue that resulted in arbitrary function execution from the WebEngine frontend to the backend is now fixed. Now only functions that are linked to available screen elements are possible to execute.

Description

The security issue that resulted in arbitrary function execution from the WebEngine frontend to the backend is now fixed. Now only functions that are linked to available screen elements are possible to execute.



Issue Number: 225691
Fixed on Date: 10.9.2020
Versions: 8.10 0 BUILD 68622 | 8.20 0 BUILD 68579
    • Related Articles

    • Function "Execute VSTA Macro" is not executed in zenon 12 for converted projects

      Description When converting a project to zenon version 12, the "Execute VSTA macro" function is not applied correctly. The VSTA code is not executed. However, the same code is executed if it is part of the "ThisProject_Active" or ...
    • zenon Service Engine freezes when process recorder is active

      Description The zenon Service Engine froze when the Process Recorder was active. The Service Engine froze because a Microsoft function runs in an endless loop. The issue has been addressed and an optimization call, which led to the issue, has been ...
    • zenon Changesets Excel

      Here, you can access a comprehensive list of changes across all maintained versions of the zenon Software Platform as Excel Worksheets. This includes both implemented bug-fixes and new features. Additionally, these lists are available in CSV format ...
    • zenon Changesets CSV

      Here, you can access a comprehensive list of changes across all maintained versions of the zenon Software Platform as Excel Worksheets. This includes both implemented bug-fixes and new features. Additionally, these lists are available in as Excel ...
    • 3D-Tool: Function execution not properly triggered when clicking on a 3D element that is linked to a function

      Summary In the zenon Service Engine 3D-Tool, clicking on an element within the 3D model does not trigger the associated function. This has been fixed. Description In very complex 3D models, rendering can lead to delays if the hardware is ...