Executive brief
iioter iotgateway is an open-source industrial IoT gateway used for protocol conversion and connecting industrial devices like PLCs to cloud platforms. A security vulnerability in the logging system allows remote attackers to inject malicious scripts into the administration interface. If an administrator views the activity logs, these scripts could execute in their browser, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in iioter iotgateway v3.0.1 and earlier within the Log Record Function. The application retrieves the user's IP address from the 'X-Forwarded-For' HTTP header without proper sanitization or validation before storing it in the database. When an administrator views the logs via the '/_Admin/ActionLog/Search' or '/_Admin/ActionLog/Details' endpoints, the malicious payload is rendered in the browser. An attacker can exploit this by sending a crafted HTTP request with a malicious script in the 'X-Forwarded-For' header, potentially leading to session hijacking or unauthorized administrative actions.
Affected products
- iioter iotgateway 3.0.1 and earlier
Timeline
- 2026-03-04: disclosed: Issue reported on GitHub repository
- 2026-05-11: advisory: CVE published to NVD