Execution of any zenon function in HTML5 Webclient by manipulating frontend JS code
Summary
The security issue that resulted in arbitrary function execution from the WebEngine frontend to the backend is now fixed. Now only functions that are linked to available screen elements are possible to execute.
Description
The security issue that resulted in arbitrary function execution from the WebEngine frontend to the backend is now fixed. Now only functions that are linked to available screen elements are possible to execute.
Issue Number: 225691
Fixed on Date: 10.9.2020
Versions: 8.10 0 BUILD 68622 | 8.20 0 BUILD 68579
Related Articles
Function "Execute VSTA Macro" is not executed in zenon 12 for converted projects
Description When converting a project to zenon version 12, the "Execute VSTA macro" function is not applied correctly. The VSTA code is not executed. However, the same code is executed if it is part of the "ThisProject_Active" or ...
zenon Service Engine freezes when process recorder is active
Description The zenon Service Engine froze when the Process Recorder was active. The Service Engine froze because a Microsoft function runs in an endless loop. The issue has been addressed and an optimization call, which led to the issue, has been ...
3D-Tool: Function execution not properly triggered when clicking on a 3D element that is linked to a function
Summary In the zenon Service Engine 3D-Tool, clicking on an element within the 3D model does not trigger the associated function. This has been fixed. Description In very complex 3D models, rendering can lead to delays if the hardware is ...
Logic Service: zenrt_write function doesn't update variables and locks writing from other sources
Description After the execution of the zenrt_write function to update the value of the zenon variable externally visible in zenon Logic, the variable values in zenon were no longer updated and could not be changed by any meaning. According logs, the ...
Machine Event Counters Report not working any more in zenon 12
Description In Report Engine version 12, the reports "Machine Event Counters", "Over Revolutions on Load Shedding" and "Active Power on Load Shedding" no longer work after they have been updated from a previous version. The error states that the ...