Execution of any zenon function in HTML5 Webclient by manipulating frontend JS code

Execution of any zenon function in HTML5 Webclient by manipulating frontend JS code

Summary

The security issue that resulted in arbitrary function execution from the WebEngine frontend to the backend is now fixed. Now only functions that are linked to available screen elements are possible to execute.

Description

The security issue that resulted in arbitrary function execution from the WebEngine frontend to the backend is now fixed. Now only functions that are linked to available screen elements are possible to execute.



Issue Number: 225691
Fixed on Date: 10.9.2020
Versions: 8.10 0 BUILD 68622 | 8.20 0 BUILD 68579