CVE-2021-31682
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitiz...
Affects 1 product across 1 vendor.
Attacker injects malicious scripts into web pages viewed by other users, executing in the victim's browser context.
Show all 6
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
The Automated Logic WebCTRL/WebCTRL OEM web application versions 6.5 and below are vulnerable to reflected XSS attacks due to unsanitized input in the operatorlocale GET parameter.
BSID: BS-2021-GLOBAL-199862-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2021-31682?
What is the CVSS score for CVE-2021-31682?
Is CVE-2021-31682 actively exploited?
How do I remediate CVE-2021-31682?
What systems are affected by CVE-2021-31682?
| CVE ID | CVE-2021-31682 |
|---|---|
| BSID | BS-2021-GLOBAL-199862-M BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| Published | 2021-10-22 |
| Last Modified | 2024-11-21 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.
Source: NIST NVD / MITRE CVE Database
An attacker can exploit this vulnerability by injecting a malicious script through the operatorlocale GET parameter. The script is then reflected in the output without proper sanitization, leading to potential execution in the context of the victim's browser.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Automatedlogic | Webctrl | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 8de1a8f647c3f782f23ac1c3438a9ace7b167e8cb6cf72b0e297a93ce636b0101776ec59cf2cf2d3b7bc434881d6a524d925d19db990b23e04752cdc96a6d9f7 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →