CVE-2021-31682

MEDIUM ⚠ Exploit

The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitiz...

Affects 1 product across 1 vendor.

BCS6.61
CVSS 3.16.1
EPSS10.5%
Percentile95th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, requires user interaction, can impact systems beyond the vulnerable component, no availability impact.
CWE Weakness Definitions
CWE-79: Cross-Site Scripting (XSS)

Attacker injects malicious scripts into web pages viewed by other users, executing in the victim's browser context.

Related Attack Patterns (CAPEC)
CAPEC-85 AJAX Footprinting
via CWE-79
CAPEC-209 XSS Using MIME Type Mismatch
via CWE-79
CAPEC-588 DOM-Based XSS
via CWE-79
CAPEC-591 Reflected XSS
via CWE-79
CAPEC-592 Stored XSS
via CWE-79
Show all 6
via CWE-79

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The Automated Logic WebCTRL/WebCTRL OEM web application versions 6.5 and below are vulnerable to reflected XSS attacks due to unsanitized input in the operatorlocale GET parameter.

BSID: BS-2021-GLOBAL-199862-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2021-31682?
The Automated Logic WebCTRL/WebCTRL OEM web application versions 6.5 and below are vulnerable to reflected XSS attacks due to unsanitized input in the operatorlocale GET parameter.
What is the CVSS score for CVE-2021-31682?
CVE-2021-31682 has CVSS 6.1 (Medium). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. EPSS: 10.5%.
Is CVE-2021-31682 actively exploited?
Public exploit available for CVE-2021-31682. Exploitation risk elevated.
How do I remediate CVE-2021-31682?
Priority: MEDIUM. Advisory: https://www.automatedlogic.com/en/products-services/webctrl-building-automation-system/ PSIRT: [email protected]
What systems are affected by CVE-2021-31682?
CVE-2021-31682 affects: Automatedlogic.
Vulnerability Details
CVE IDCVE-2021-31682
BSIDBS-2021-GLOBAL-199862-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Published2021-10-22
Last Modified2024-11-21
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by injecting a malicious script through the operatorlocale GET parameter. The script is then reflected in the output without proper sanitization, leading to potential execution in the context of the victim's browser.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Automatedlogic Webctrl
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1737 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash8de1a8f647c3f782f23ac1c3438a9ace7b167e8cb6cf72b0e297a93ce636b0101776ec59cf2cf2d3b7bc434881d6a524d925d19db990b23e04752cdc96a6d9f7
Related CVEs affecting Automatedlogic
CVE-2017-9650 7.8 An Unrestricted Upload of File with Dangerous Type issue was discovered in Au... CVE-2026-32666 7.5 WebCTRL systems that communicate over BACnet inherit the protocol's lack of ... CVE-2016-5795 7.3 An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert Site... CVE-2017-9644 7.0 An Unquoted Search Path or Element issue was discovered in Automated Logic Co... CVE-2017-9640 6.3 A Path Traversal issue was discovered in Automated Logic Corporation (ALC) AL...
View all Automatedlogic CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →