CVE-2019-11643
Last modified
CVE-2019-11643 is a vulnerability of currently unknown severity. Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to the applicable data store. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to the applicable data store. This can be exploited remotely by both authenticated and unauthenticated users.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oneshield | Oneshield Policy | < 5.1.10 |
References
- http://seclists.org/fulldisclosure/2019/May/2Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/May/2Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11643?
How severe is CVE-2019-11643?
How do I fix CVE-2019-11643?
Are you affected by CVE-2019-11643?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
